>DevOps Interview KB

AWS Interview Questions

39 questions

AWS interview questions built around real production judgment, not service trivia — IAM least-privilege design and incident response, Lambda cold-start and concurrency trade-offs, and S3 exposure prevention and fast alerting. Each thread goes deep on one realistic scenario rather than skimming many services shallowly, covering beginner fundamentals through expert-level architecture and troubleshooting.

How would you audit whether an ECS task role or Lambda execution role is actually scoped tightly, versus just copy-pasted from a broader existing role?

AdvancedAWS7 min

What CloudTrail-based alerting would you specifically set up for a narrowly-scoped static-key IAM user, and how would you tune it to avoid false positives?

AdvancedAWS7 min

How would you design the exception process for an SCP blocking IAM user creation, so legitimate cases aren't blocked indefinitely by bureaucracy?

AdvancedAWS7 min

How does the workload-identity comparison extend to EKS, where pod identity is yet another mechanism (IRSA or Pod Identity)?

ExpertAWSEKSKubernetes8 min

What's the mechanism difference between how EC2's IMDS delivers credentials versus how Lambda delivers them to a function's environment?

AdvancedAWSLambda6 min

How would you make the case for the cost of a separate AWS account, if leadership pushes back on the added complexity?

IntermediateAWS6 min

How does the approach to workload identity and least privilege differ if a workload runs on ECS or Lambda instead of EC2?

IntermediateAWSECSLambda7 min

You inherit an EC2 workload that authenticates to AWS using an IAM user with AdministratorAccess. How would you migrate it to least-privilege access without causing an outage?

AdvancedAWSIAMEC212 min

How would you measure whether an IAM governance change (like an SCP blocking user creation) actually worked, six months later?

IntermediateAWS6 min

How would you prevent a new workload from ever being built directly on a static IAM user again, at an organizational level rather than case by case?

AdvancedAWS8 min

A detective scan finds dozens of pre-existing IAM users with active keys across many accounts. How would you prioritize remediation?

AdvancedAWS7 min

How would you design automated credential rotation to handle the overlap window safely, so the application never experiences an auth failure?

AdvancedAWS7 min

A third-party application only supports static AWS access keys and can't use an instance profile or role. How do you handle this without abandoning least privilege entirely?

AdvancedAWS8 min