DevOps Engineer Interview Questions
372 questions across 38 categories
The bulk of a working DevOps engineer's day-to-day: hands-on tooling, common troubleshooting, and the practical judgment calls that come up once you're actually operating systems.
How would you make the case for the cost of a separate AWS account, if leadership pushes back on the added complexity?
IntermediateAWS6 min
How does the approach to workload identity and least privilege differ if a workload runs on ECS or Lambda instead of EC2?
IntermediateAWSECSLambda7 min
How would you measure whether an IAM governance change (like an SCP blocking user creation) actually worked, six months later?
IntermediateAWS6 min
How would you detect, from CloudWatch metrics alone, whether a Lambda function's tail latency problem is cold-start-driven versus something else?
IntermediateAWSLambdaCloudwatch7 min
How does AWS Lambda's execution environment reuse actually work, and why does that make cold starts disproportionately affect low-traffic or bursty functions?
IntermediateAWSLambda7 min
Why does Lambda initialization code placed outside the handler function only run once per environment, and how would you use that intentionally?
IntermediateAWSLambda6 min
What's the cost/latency trade-off of using Provisioned Concurrency versus just increasing a Lambda function's timeout to absorb cold starts?
IntermediateAWSLambda6 min
How does Provisioned Concurrency eliminate Lambda cold starts on demand, and what does that actually cost?
IntermediateAWSLambda6 min
What's the difference between Lambda Provisioned Concurrency and Lambda SnapStart, and when would each be the better fit?
IntermediateAWSLambda6 min
How would you size Provisioned Concurrency for a Lambda function with a predictable daily peak but otherwise low traffic?
IntermediateAWSLambda6 min
A Lambda function times out for about 2% of invocations, seemingly at random, but works fine when you test it manually. How would you track down the cause?
IntermediateAWSLambda10 min
How would you handle the allowlisting process for intentionally-public S3 buckets so it doesn't become its own source of friction or forgotten debt?
IntermediateAWSS36 min
What's the difference between S3 Block Public Access and a restrictive bucket policy, and why is Block Public Access the stronger tool during an active exposure incident?
IntermediateAWSS36 min
What's the difference between S3's 'block public ACLs' and 'restrict public buckets' as individual Block Public Access settings?
IntermediateAWSS36 min
How would you measure whether an S3 public-exposure alerting system is actually working, short of waiting for a real incident?
IntermediateAWS6 min
What preventive controls would make an S3 public-write exposure incident less damaging in the future — bucket policies, Object Lock, or something else?
IntermediateAWSS36 min
Why might an organization choose not to enable account-level S3 Block Public Access by default, and what legitimate use case would that block?
IntermediateAWSS36 min