# Settings & Production Configuration (Django) > Settings split (base/dev/prod), secrets management, ALLOWED_HOSTS, CSRF_TRUSTED_ORIGINS, SECURE_* settings, .env/vault, storage configuration - 22 interview questions - Senior - [Interview Questions: Django](https://sharpskill.dev/en/technologies/django/interview-questions.md) ## 1. What is the recommended structure for organizing Django settings files in production? **Answer** The recommended structure involves creating a settings package with a base.py file containing common configurations, then separate dev.py, staging.py and prod.py files that import and extend base.py. This approach allows sharing common configuration while customizing specific environments, making maintenance easier and reducing code duplication. ## 2. How to specify which settings file to use when starting a Django project? **Answer** The DJANGO_SETTINGS_MODULE environment variable specifies the Python path to the settings module to use. For example, DJANGO_SETTINGS_MODULE=myproject.settings.prod tells Django to use the prod.py file from the settings package. This variable can be set in the shell, server configuration files or deployment scripts. ## 3. What is the purpose of the ALLOWED_HOSTS setting in Django? **Answer** ALLOWED_HOSTS is a list of domains/hosts allowed to serve the Django application. This security mechanism protects against HTTP Host header attacks by validating the Host header of each request. In production with DEBUG=False, this setting is mandatory and must contain the legitimate domains of the application to avoid 400 Bad Request errors. ## 19 more questions available - What ALLOWED_HOSTS value accepts any host, and why is it dangerous in production? - What is the purpose of the CSRF_TRUSTED_ORIGINS setting introduced in Django 4.0? Sign up for free: https://sharpskill.dev/en/login ## Other Django interview topics - [Python Basics](https://sharpskill.dev/en/technologies/django/interview-questions/python-basics.md): 25 questions, Junior - [Python OOP](https://sharpskill.dev/en/technologies/django/interview-questions/python-oop.md): 20 questions, Junior - [Django Fundamentals](https://sharpskill.dev/en/technologies/django/interview-questions/django-fundamentals.md): 20 questions, Junior - [Django Models - Basics](https://sharpskill.dev/en/technologies/django/interview-questions/django-models-basics.md): 22 questions, Junior - [Django Views](https://sharpskill.dev/en/technologies/django/interview-questions/django-views.md): 20 questions, Junior - [Django Templates](https://sharpskill.dev/en/technologies/django/interview-questions/django-templates.md): 18 questions, Junior - [Django Forms](https://sharpskill.dev/en/technologies/django/interview-questions/django-forms.md): 22 questions, Mid-Level - [Advanced QuerySets](https://sharpskill.dev/en/technologies/django/interview-questions/django-querysets.md): 25 questions, Mid-Level - [Django Authentication](https://sharpskill.dev/en/technologies/django/interview-questions/django-authentication.md): 22 questions, Mid-Level - [Django Middleware](https://sharpskill.dev/en/technologies/django/interview-questions/django-middleware.md): 18 questions, Mid-Level - [Django Admin](https://sharpskill.dev/en/technologies/django/interview-questions/django-admin.md): 20 questions, Mid-Level - [Django REST Framework](https://sharpskill.dev/en/technologies/django/interview-questions/django-rest-framework.md): 30 questions, Mid-Level - [Django Signals](https://sharpskill.dev/en/technologies/django/interview-questions/django-signals.md): 18 questions, Mid-Level - [File Upload](https://sharpskill.dev/en/technologies/django/interview-questions/django-file-upload.md): 20 questions, Mid-Level - [Django Caching](https://sharpskill.dev/en/technologies/django/interview-questions/django-caching.md): 20 questions, Mid-Level - [Django Sessions](https://sharpskill.dev/en/technologies/django/interview-questions/django-sessions.md): 18 questions, Mid-Level - [Django Email](https://sharpskill.dev/en/technologies/django/interview-questions/django-email.md): 18 questions, Mid-Level - [Django Testing](https://sharpskill.dev/en/technologies/django/interview-questions/django-testing.md): 22 questions, Mid-Level - [Django Security](https://sharpskill.dev/en/technologies/django/interview-questions/django-security.md): 22 questions, Mid-Level - [Django Deployment](https://sharpskill.dev/en/technologies/django/interview-questions/django-deployment.md): 24 questions, Mid-Level - [Advanced Django ORM](https://sharpskill.dev/en/technologies/django/interview-questions/django-orm-advanced.md): 28 questions, Senior - [Django Performance](https://sharpskill.dev/en/technologies/django/interview-questions/django-performance.md): 24 questions, Senior - [Django & Celery](https://sharpskill.dev/en/technologies/django/interview-questions/django-celery.md): 22 questions, Senior - [Django Channels](https://sharpskill.dev/en/technologies/django/interview-questions/django-channels.md): 24 questions, Senior - [Django & GraphQL](https://sharpskill.dev/en/technologies/django/interview-questions/django-graphql.md): 24 questions, Senior - [Django & Docker](https://sharpskill.dev/en/technologies/django/interview-questions/django-docker.md): 20 questions, Senior - [Django in Microservices Ecosystem](https://sharpskill.dev/en/technologies/django/interview-questions/django-microservices.md): 24 questions, Senior - [Custom Django Commands](https://sharpskill.dev/en/technologies/django/interview-questions/django-custom-commands.md): 18 questions, Senior - [Django Internationalization](https://sharpskill.dev/en/technologies/django/interview-questions/django-internationalization.md): 20 questions, Senior - [Django Design Patterns](https://sharpskill.dev/en/technologies/django/interview-questions/django-design-patterns.md): 24 questions, Senior - [Django Async & ASGI](https://sharpskill.dev/en/technologies/django/interview-questions/django-async-asgi.md): 26 questions, Senior - [Observability & Monitoring](https://sharpskill.dev/en/technologies/django/interview-questions/django-observability.md): 24 questions, Senior --- Source: SharpSkill (https://sharpskill.dev), tech interview preparation for your real stack. HTML version of this page: https://sharpskill.dev/en/technologies/django/interview-questions/django-settings-configuration