REST Assured interview questions — Hard
159 hard-level REST Assured questions from our API Testing bank, each with the correct answer and an explanation of why it is correct.
What this covers
REST Assured appears throughout API Testing interviews. At hard level, interviewers are typically checking depth under pressure — edge cases, failure modes, performance characteristics, and the trade-offs you accepted. Work through these, then explain your answer out loud; the second part is what interviews actually test.
8 example questions
1. On a release readiness call: How do you assert data.id == 5 in a REST Assured body?
- A. Body("data.id", equalTo(5)).correct
- B. AssertEquals(5).
- C. Then().json(5).
- D. Expect(5).
Why: REST Assured uses JsonPath with Hamcrest matchers.
2. Regarding REST Assured, which of the following is a false statement?
- A. REST Assured cannot validate nested JSON fields.correct
- B. REST Assured integrates with Hamcrest matchers for expressive assertions.
- C. Extract().path() pulls values from a response for use in subsequent requests.
- D. REST Assured uses a BDD-style given/when/then syntax for API tests in Java.
Why: The selected statement is false. The other options are accurate statements about REST Assured.
3. Which of the following statements about REST Assured is FALSE?
- A. REST Assured uses a BDD-style given/when/then syntax for API tests in Java.
- B. REST Assured supports logging of requests and responses for debugging with log().all().
- C. REST Assured cannot validate nested JSON fields.correct
- D. REST Assured integrates with Hamcrest matchers for expressive assertions.
Why: The selected statement is false. The other options are accurate statements about REST Assured.
4. What does .extract().path("token") accomplish in a REST Assured chain?
- A. Sends a new request.
- B. Pulls a value out of the response so it can be reused (e.g., chaining auth).correct
- C. Asserts the response time.
- D. Logs the request headers.
Why: extract() lets you pull values (via JsonPath) out of a response to reuse later — common for grabbing an auth token from a login call.
5. Identify the INCORRECT statement about REST Assured:
- A. RequestSpecification allows reusing common settings like base URI and headers across tests.
- B. REST Assured can handle authentication schemes including Basic, OAuth2, and form auth.
- C. Body("path", equalTo(value)) validates JSON response fields using GPath expressions.
- D. REST Assured has no support for OAuth2 authentication.correct
Why: The selected statement is false. The other options are accurate statements about REST Assured.
6. Which statement about REST Assured is NOT correct?
- A. REST Assured can handle authentication schemes including Basic, OAuth2, and form auth.
- B. Body("path", equalTo(value)) validates JSON response fields using GPath expressions.
- C. REST Assured uses a BDD-style given/when/then syntax for API tests in Java.
- D. RequestSpecification must be redefined inside every single test.correct
Why: The selected statement is false. The other options are accurate statements about REST Assured.
7. During a sprint demo, a teammate asks: REST Assured tests use which readable style?
- A. Arrange/act/assert.
- B. Given()/when()/then().correct
- C. Open/send/close.
- D. Setup/run/verify.
Why: REST Assured uses BDD-style given/when/then.
8. extract().path("token") is used to:
- A. Send a request.
- B. Assert time.
- C. Pull a value from the response for reuse.correct
- D. Log headers.
Why: extract() pulls values (JsonPath) to reuse, e.g. an auth token.