Which security headers should a MERN stack send?
PICTURE THIS: A REST CALL
Simple meaning
Use HTTPS-only cookies, HSTS, a Content-Security-Policy for the React app, X-Content-Type-Options, and a tight Referrer-Policy.
WHY — Security instead of guessing?
Why interviewers care about Security:
who only read docs from people who shipped.
and tied to Full Stack work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Use HTTPS-only cookies, HSTS,
a Content-Security-Policy for the React app, X-Content-Type-Options, and a tight Referrer-Policy.
- 2Why it exists
helmet helps on Express
- 3nginx can add headers
for static files.
- 4Headers reduce impact but
do not replace input validation.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Use HTTPS-only cookies, HSTS, a Content-Security-Policy for the React app, X-Content-Type-Options, and a tight Referrer-Policy. helmet helps on Express