# Security & Best Practices (Angular) > XSS protection, CSRF, sanitization, DomSanitizer, Content Security Policy, authentication, authorization, JWT - 20 interview questions - Senior - [Interview Questions: Angular](https://sharpskill.dev/en/technologies/angular/interview-questions.md) ## 1. What is an XSS (Cross-Site Scripting) attack? **Answer** An XSS attack involves injecting malicious JavaScript code into a web application to execute it in users' browsers. The attacker exploits validation flaws to steal sensitive data (cookies, tokens) or manipulate the DOM. Angular automatically protects against this type of attack through sanitization of content injected into templates. ## 2. How does Angular automatically protect against XSS attacks? **Answer** Angular automatically sanitizes all values injected into templates via interpolation or property binding. The DomSanitizer analyzes the content and removes any potentially dangerous code before displaying it. This protection is applied by default without additional configuration, ensuring that untrusted HTML, URLs, and styles are cleaned. ## 3. What is the DomSanitizer in Angular? **Answer** DomSanitizer is an Angular service that cleans untrusted content before injecting it into the DOM. It analyzes HTML, URLs, styles, and scripts to detect and remove potentially dangerous elements. This service also provides bypassSecurityTrust* methods to explicitly mark content as safe when the source is trusted and verified. ## 17 more questions available - In which contexts does Angular apply automatic sanitization? - What is a CSRF (Cross-Site Request Forgery) attack? Sign up for free: https://sharpskill.dev/en/login ## Other Angular interview topics - [TypeScript Basics](https://sharpskill.dev/en/technologies/angular/interview-questions/typescript-basics.md): 25 questions, Junior - [TypeScript Advanced](https://sharpskill.dev/en/technologies/angular/interview-questions/typescript-advanced.md): 20 questions, Junior - [Angular Fundamentals](https://sharpskill.dev/en/technologies/angular/interview-questions/angular-fundamentals.md): 20 questions, Junior - [Components & Lifecycle](https://sharpskill.dev/en/technologies/angular/interview-questions/components-lifecycle.md): 20 questions, Junior - [Services & Dependency Injection](https://sharpskill.dev/en/technologies/angular/interview-questions/services-dependency-injection.md): 20 questions, Junior - [Angular Modules Organization](https://sharpskill.dev/en/technologies/angular/interview-questions/modules-organization.md): 22 questions, Mid-Level - [Angular CLI](https://sharpskill.dev/en/technologies/angular/interview-questions/angular-cli.md): 18 questions, Junior - [Directives & Pipes](https://sharpskill.dev/en/technologies/angular/interview-questions/directives-pipes.md): 22 questions, Mid-Level - [Routing & Navigation](https://sharpskill.dev/en/technologies/angular/interview-questions/routing-navigation.md): 24 questions, Mid-Level - [Reactive Forms](https://sharpskill.dev/en/technologies/angular/interview-questions/forms-reactive.md): 26 questions, Mid-Level - [Template-driven Forms](https://sharpskill.dev/en/technologies/angular/interview-questions/forms-template-driven.md): 16 questions, Mid-Level - [RxJS Fundamentals](https://sharpskill.dev/en/technologies/angular/interview-questions/rxjs-fundamentals.md): 22 questions, Mid-Level - [RxJS Operators](https://sharpskill.dev/en/technologies/angular/interview-questions/rxjs-operators.md): 24 questions, Mid-Level - [HttpClient & API Calls](https://sharpskill.dev/en/technologies/angular/interview-questions/http-client.md): 22 questions, Mid-Level - [Basic State Management](https://sharpskill.dev/en/technologies/angular/interview-questions/state-management-basics.md): 20 questions, Mid-Level - [Change Detection](https://sharpskill.dev/en/technologies/angular/interview-questions/change-detection.md): 20 questions, Mid-Level - [Angular Signals](https://sharpskill.dev/en/technologies/angular/interview-questions/angular-signals.md): 20 questions, Mid-Level - [Standalone Components](https://sharpskill.dev/en/technologies/angular/interview-questions/standalone-components.md): 18 questions, Mid-Level - [Angular Unit Testing](https://sharpskill.dev/en/technologies/angular/interview-questions/testing-unit.md): 22 questions, Mid-Level - [End-to-End Testing](https://sharpskill.dev/en/technologies/angular/interview-questions/testing-e2e.md): 18 questions, Mid-Level - [Build & Optimization](https://sharpskill.dev/en/technologies/angular/interview-questions/build-optimization.md): 20 questions, Mid-Level - [NgRx Fundamentals](https://sharpskill.dev/en/technologies/angular/interview-questions/ngrx-fundamentals.md): 24 questions, Senior - [NgRx Advanced](https://sharpskill.dev/en/technologies/angular/interview-questions/ngrx-advanced.md): 24 questions, Senior - [Angular Architecture](https://sharpskill.dev/en/technologies/angular/interview-questions/angular-architecture.md): 22 questions, Senior - [Performance Optimization](https://sharpskill.dev/en/technologies/angular/interview-questions/performance-optimization.md): 22 questions, Senior - [Advanced RxJS Patterns](https://sharpskill.dev/en/technologies/angular/interview-questions/advanced-rxjs-patterns.md): 22 questions, Senior - [Angular Universal & SSR](https://sharpskill.dev/en/technologies/angular/interview-questions/angular-universal-ssr.md): 20 questions, Senior - [Angular Micro-frontends](https://sharpskill.dev/en/technologies/angular/interview-questions/micro-frontends-angular.md): 20 questions, Senior --- Source: SharpSkill (https://sharpskill.dev), tech interview preparation for your real stack. HTML version of this page: https://sharpskill.dev/en/technologies/angular/interview-questions/security-best-practices