Asp.Net interview prep is mostly about knowing what trips people up
I've sat on both sides of these interviews for years. The fresher wave comes in with framework definitions memorized from tutorials, which is fine, but the ones who get hired are the ones who can talk about what actually breaks in production. Let me walk through some of the questions that come up most often and what a solid answer looks like. What is the difference between ASP.NET Web Forms and ASP.NET MVC? Web Forms uses a page lifecycle driven by ViewState and server controls. MVC separates concerns into Models, Views, and Controllers with explicit HTTP handling. If you're maintaining a legacy app built in 2012 with update panels and postbacks, that's Web Forms. If you're building something with REST endpoints and clean URLs, that's MVC or Core. Both still exist in the wild.
Explain the ASP.NET page lifecycle. It goes from Init, LoadViewState, LoadPostData, Load, PostBackEventHandling, RaisePostBackEvents, SaveStateComplete, Render, to Unload. You don't need to recite every step in order during an interview. What matters is knowing that ViewState loads after Init but before Load, and if you try to read a control's value in Init, it hasn't been restored yet. I once spent three hours debugging a validation bug that turned out to be someone reading a textbox value in the wrong lifecycle stage. The fix was moving that logic to Page_Load instead. What is ViewState and when should you avoid using it?
ViewState serializes control state into a base64 hidden field on the page. It's automatic in Web Forms, which means every postback carries that data back and forth. Avoid it when you're dealing with large datasets or sensitive information since it's visible in the page source unless you encrypt it. Turning off ViewState at the page level cut our average response size from 180KB down to about 45KB on a reporting dashboard we inherited. What is the difference between session state, application state, and cache? Session state is per-user and lives either in-process, in a state server, or in SQL Server depending on your configuration. Application state is global across all users and only exists in the AppDomain, so it's lost on restart. Cache is the same but with expiration policies and dependency tracking. Use cache for shared data that changes infrequently, session for per-user preferences, and never application state for anything that needs to survive an app pool recycle.
Get the Full Details

How does dependency injection work in ASP.NET Core? ASP.NET Core has a built-in DI container. You register services in Startup or Program.cs using AddSingleton, AddScoped, or AddTransient. Singleton lives for the entire app lifetime, Scoped lives per HTTP request, and Transient is created every time you ask for it. The framework resolves the graph automatically when it constructs your controller or service. The most common mistake freshers make is injecting a scoped service into a singleton, which causes a captured dependency problem. The container throws at runtime if you configure it wrong, but the fix isn't obvious unless you know what the scope violation means. What is middleware in ASP.NET Core?
Middleware is a pipeline component that handles requests and responses. You configure it in the request pipeline and each piece can short-circuit or pass to the next one. Authentication, logging, error handling, routing, and static files are all middleware. The order matters. If you put your error handler after your endpoint mapping, exceptions won't get caught properly. I've seen production issues where a missing UseAuthentication call meant the entire security layer was bypassed because someone reordered the pipeline without realizing what they were doing. Explain Web API versus MVC controllers. Web API controllers return data, usually JSON or XML, and map to HTTP methods directly. MVC controllers return views and work with the razor rendering pipeline. In ASP.NET Core they're unified under ControllerBase and Controller respectively. The key distinction is that API endpoints don't have a view engine attached to them. If you're building a frontend that talks to a backend separately, you want Web API. If you're serving full pages from the server, MVC is still relevant for legacy projects.
What are authentication and authorization in ASP.NET? Authentication verifies who you are. Authorization checks what you're allowed to do. ASP.NET Identity handles authentication with cookies, JWT tokens, or OAuth providers. Authorization uses policies and roles. A fresh question to drill into is the difference between [Authorize] at the controller level versus the action level, and how authorization policies differ from role-based checks. Policies let you define custom requirements like minimum age or subscription tier without rewriting role logic everywhere. How do you handle errors in ASP.NET Core?

You can use UseExceptionHandler, UseStatusCodePages, or custom middleware. For development, the developer exception page gives you stack traces. For production, you'd want a centralized error handler that logs the exception and returns a generic response. Filters like ExceptionFilterAttribute work too but middleware is preferred now because it catches errors that happen outside the MVC pipeline. I once had an issue where an unhandled exception in a background worker was silently failing because it bypassed the request pipeline entirely. The fix was wrapping the background task in its own try-catch with Serilog output instead of relying on the global exception handler. What is Entity Framework and when should you not use it? EF is an ORM that maps database tables to Cclasses. EF Core is the current version and it's significantly faster than the original Entity Framework. The tradeoff is that for complex queries involving multiple joins and aggregation, the generated SQL can be inefficient. I've seen queries that took 200 milliseconds with raw SQL get dragged to 8 seconds through EF's navigation property loading. When performance is critical, I drop to Dapper or write the query directly. EF is excellent for CRUD operations and rapid development, not for heavy analytical queries.
What is a lambda expression and how is it used in ASP.NET? A lambda is an anonymous function using the => operator. You'll see it everywhere in LINQ queries, in predicate filters, and in configuring middleware. It's not framework-specific, but ASP.NET uses it constantly for things like filtering collections or setting up routes. Knowing how to read and write lambdas is basically required because you'll encounter them in every codebase. How do you configure a connection string in ASP.NET Core?
Connection strings live in appsettings.json and are loaded through the configuration system. You access them via IConfiguration in your startup or DI container. Never hardcode connection strings. Use environment-specific configuration so your dev database doesn't overwrite production data. I've seen this mistake happen more than once in small teams where someone forgot the environment override was missing and the app pointed at a staging DB instead of production. What is the difference between TempData, ViewData, and ViewBag? This question comes up a lot in Web Forms to MVC transition interviews. ViewData is a dictionary accessible in the controller and view. ViewBag is a dynamic wrapper around ViewData. TempData persists data across a single redirect, which is useful for success messages after a POST. The catch with TempData is that it gets consumed on the first read, so if you need it twice, you have to call Keep on it. I learned that one the hard way when a confirmation message disappeared mid-flow because the controller accessed it twice during an error recovery path.
Explain the concept of async and await in ASP.NET. Async operations don't block the thread while waiting for I/O like database calls or HTTP requests. You mark methods with async and use await to yield control back. In ASP.NET this prevents thread pool exhaustion under load. The key thing to understand is that async doesn't make individual operations faster, it makes your application handle more concurrent requests with fewer threads. Returning Task
This overlaps with the DI question but deserves a separate answer because scope violations are the #1 mistake I see in junior code. Transient creates a new instance every time. Scoped creates one per HTTP request. Singleton creates one for the app lifetime. If a transient service depends on a scoped service, that's fine. If a scoped service depends on a singleton, that's also fine. But if a singleton depends on a scoped service, the scoped service gets captured for the singleton's lifetime, which breaks per-request behavior. The compiler won't stop you from writing this, but the runtime will throw when you try to resolve it. How do you implement CORS in ASP.NET Core? You add a CORS policy in the configuration and apply it in the pipeline. By default, ASP.NET Core blocks cross-origin requests. You define which origins, methods, and headers are allowed. The common pitfall is placing the UseCors middleware after the UseRouting call. It needs to be before middleware that handles responses, otherwise the preflight OPTIONS request won't get the right headers. I spent an afternoon debugging a frontend issue where the browser was rejecting requests and the problem was exactly this ordering mistake.
What is the difference between IFormFile and FileResult? IFormFile is what you use to receive uploaded files in a POST request. FileResult is what you return to send a file download to the client. They sound similar but operate in opposite directions. If you're building a file upload endpoint, you accept IFormFile, validate the content type and size, then process or store it. If you're serving files back, you return FileResult with the correct MIME type so the browser handles it properly. How does caching work in ASP.NET Core?

There's in-memory caching through IMemoryCache, distributed caching through IDistributedCache for multi-server scenarios, and response caching through attributes or middleware. In-memory caching is simple but doesn't survive app restarts or scale across servers. Distributed caching with Redis or SQL Server is better for production but adds infrastructure complexity. Response caching is useful for reducing redundant computation on repeated requests but can serve stale data if you're not careful about cache invalidation. I've seen APIs return outdated data for hours because someone set a long expiration without a cache key that accounted for the underlying data changing. What is the purpose of the wwwroot folder? It's the default folder for static files like CSS, JavaScript, images, and fonts. The static file middleware serves files from this directory. You configure it with UseStaticFiles. Anything outside wwwroot isn't accessible directly through the web server unless you explicitly allow it. This is a security boundary, not just a convention.
How do you unit test an ASP.NET Core controller? You create a test project, instantiate the controller with mocked dependencies, call the action method, and assert on the result. The trick is that controllers should depend on abstractions, not concrete implementations, so you can inject mocks. If your controller calls a database directly, you can't unit test it without spinning up an actual database. That's an integration test, not a unit test. Keep them separate. The Microsoft Testing framework or xUnit works fine for this. Moq is the standard mocking library. What is the difference between ASP.NET Core and ASP.NET 4.x?
ASP.NET Core is cross-platform, open-source, and modular. ASP.NET 4.x runs only on Windows with IIS. Core uses a lightweight Kestrel server by default and supports docker containers natively. The project structure is different, the configuration system is different, and the middleware pipeline replaced the old HTTP module system. Migration between them is not trivial because many Web Forms features don't exist in Core. If you're starting fresh, learn Core. If you're maintaining a 4.x app, expect to learn the differences as you go.
