>DevOps Interview KB

Cloud Engineer Interview Questions

120 questions across 5 categories

Cloud-provider-specific depth — AWS, Azure, GCP — architecture, cost, and the platform-specific judgment calls each provider demands.

A Lambda function times out for about 2% of invocations, seemingly at random, but works fine when you test it manually. How would you track down the cause?

IntermediateAWSLambda10 min

How would you tune a hedge-request delay so it targets genuine cold-start tail latency without firing on every normal request?

AdvancedAWSLambda7 min

How would you audit all S3 buckets in an account for their current Block Public Access and policy configuration, at scale?

AdvancedAWSS37 min

How would you handle the allowlisting process for intentionally-public S3 buckets so it doesn't become its own source of friction or forgotten debt?

IntermediateAWSS36 min

What's the difference between S3 Block Public Access and a restrictive bucket policy, and why is Block Public Access the stronger tool during an active exposure incident?

IntermediateAWSS36 min

What's the difference between S3's 'block public ACLs' and 'restrict public buckets' as individual Block Public Access settings?

IntermediateAWSS36 min

How would you decide whether an S3 public-write exposure is a supply-chain security incident requiring broader notification, versus a contained issue?

AdvancedAWSS37 min

How would you determine, after an S3 public-write exposure, exactly which objects were added, modified, or deleted if versioning wasn't enabled?

AdvancedAWSS37 min

How would you measure whether an S3 public-exposure alerting system is actually working, short of waiting for a real incident?

IntermediateAWS6 min

What preventive controls would make an S3 public-write exposure incident less damaging in the future — bucket policies, Object Lock, or something else?

IntermediateAWSS36 min

A security scanner just flagged one of your production S3 buckets as publicly readable. Walk through how you'd respond in the first hour and prevent a repeat.

AdvancedAWSS3Security10 min

How would you design alerting so a public S3 exposure is caught within minutes, rather than being discovered by an external scanner or a customer report?

AdvancedAWSS38 min

How would your incident response differ if an exposed S3 bucket allowed public write access, not just public read?

AdvancedAWSS38 min

How would you scale S3 public-exposure alerting for an organization with hundreds of AWS accounts, where per-account Config rules alone don't scale operationally?

ExpertAWS8 min

Why might an organization choose not to enable account-level S3 Block Public Access by default, and what legitimate use case would that block?

IntermediateAWSS36 min

How does the Kubernetes cluster autoscaler decide which node pool to scale when multiple pools could satisfy a pending pod?

AdvancedAzureKubernetesAKS7 min

Your AKS cluster is under CPU pressure and pods are stuck Pending, but the cluster autoscaler isn't adding nodes. How would you troubleshoot it?

AdvancedAzureKubernetesAKS10 min

Should a new AKS cluster use native Kubernetes RBAC or Azure RBAC for Kubernetes Authorization to control kubectl-level access, and what does the Azure option actually change?

IntermediateAzureKubernetesAKS6 min

You're standing up a new AKS cluster and need to choose a network plugin: Azure CNI or kubenet. What's the actual trade-off, and why can this decision be hard to reverse later?

IntermediateAzureKubernetesAKS7 min

How would Karpenter-style node provisioning change the troubleshooting process compared to the traditional Kubernetes cluster autoscaler?

AdvancedKubernetes7 min

A new LoadBalancer-type Service in AKS has been stuck in 'Pending' with no external IP for twenty minutes. How do you actually diagnose this in Azure specifically?

IntermediateAzureKubernetesAKS6 min

A team converted their AKS cluster to a private cluster for security reasons. The next day, several engineers and a CI/CD pipeline can no longer run kubectl commands at all. How do you diagnose this?

AdvancedAzureKubernetesAKS7 min

During a live incident, how would you distinguish a genuinely slow autoscaler scale-up from one that's actually stuck and won't complete on its own?

IntermediateAzureKubernetesAKS7 min

How would you let a pod in AKS call a Key Vault or Storage API using its own Azure identity, without mounting any credential file or secret into the pod at all?

AdvancedAzureKubernetesAKS7 min