Intermediate DevOps Interview Questions
322 questions
An audit finds most of your EC2 instances are running at under 15% average CPU utilization. How would you approach rightsizing them without risking a performance incident?
IntermediateAWS6 min
This month's cloud bill came in 3x higher than usual, with no corresponding increase in traffic or deliberate infrastructure change. How do you actually track down the cause?
IntermediateAWS8 min
What's the actual difference between RPO and RTO, and how does each change depending on whether you're designing for multi-AZ or multi-region failover?
IntermediateAWS6 min
How would you evaluate whether to move an existing IaaS-hosted application to a PaaS, given the migration cost involved?
IntermediateCloud7 min
A customer asks how their data stays isolated from other customers on the same physical cloud infrastructure. What's actually happening under the hood to make multi-tenancy safe?
IntermediateCloud Fundamentals6 min
What operational risks does heavy reliance on SaaS introduce that IaaS or PaaS generally don't — vendor lock-in and data portability included?
IntermediateCloud6 min
Where does serverless (e.g. AWS Lambda) actually fit on the IaaS/PaaS/SaaS spectrum — does it fit cleanly into any of those three categories at all?
IntermediateAWS6 min
Leadership is nervous about 'vendor lock-in' and wants every architectural decision evaluated for portability across cloud providers. Is this concern well-founded, or often overstated?
IntermediateCloud Fundamentals6 min
How would you explain the security trade-off between containers and VMs to someone deciding whether to run untrusted third-party code?
IntermediateContainers6 min
What specific Linux namespace types exist, and what does each one actually isolate for a containerized process?
IntermediateLinuxContainers7 min
Kubernetes dropped direct Docker support years ago in favor of containerd/CRI-O. What's the actual relationship between Docker, containerd, and CRI-O, and why did this change happen?
IntermediateContainersKubernetes7 min
What does it actually mean for a container image to be 'OCI-compliant,' and why does that matter beyond just being a compatibility buzzword?
IntermediateContainers6 min
How does a container image's layered filesystem actually work at the OS level — what makes writes inside a running container not modify the underlying image?
IntermediateContainersLinux6 min
Your database backups have been running successfully every night for two years, but nobody has ever actually restored one. Why is that a real risk, and how would you fix it?
IntermediateDatabases6 min
Under a traffic spike, your application starts throwing 'too many connections' errors from the database, even though the database itself isn't under heavy CPU or memory load. What's happening?
IntermediateDatabases7 min
Your company's microservices architecture has oddly chatty, tightly-coupled services that mirror exactly how your engineering org is divided into teams. Is that a coincidence?
IntermediateDevops6 min
A team's definition of 'done' for infrastructure changes is just 'terraform apply succeeded.' What's actually missing from that definition, and why does it matter?
IntermediateDevops6 min
A team is proud that their service hasn't had a major incident in 8 months, but when something does break, it takes hours to recover. Which reliability metric should they actually be optimizing for?
IntermediateDevops6 min
What's the actual difference between idempotency and "safe to re-run" — can a task be safely re-run without actually being idempotent?
IntermediateDevops6 min
How would you tell whether a company's "Platform Engineering" team is genuinely building self-service tooling, versus just being the old ops team under a new name?
IntermediatePlatform Engineering6 min
Joining a company with none of DevOps, SRE, or Platform Engineering formalized, which would you introduce first, and why?
IntermediateDevops7 min
What's the trade-off between running security scans as a separate CI job versus as a local pre-commit/pre-push hook?
IntermediateDevSecOps6 min
How would you measure whether engineers are actually acting on security scan findings, versus just dismissing them to unblock their PR?
IntermediateDevSecOps6 min
How would you handle a pre-existing backlog of medium-severity security findings that predates your new scanning rollout, without blocking every team's work on day one?
IntermediateDevSecOps7 min