DevSecOps Interview Questions
72 questions across 16 categories
Security integrated into the delivery pipeline — supply chain, secrets management, access control, and shifting security left.
You inherit an EC2 workload that authenticates to AWS using an IAM user with AdministratorAccess. How would you migrate it to least-privilege access without causing an outage?
AdvancedAWSIAMEC212 min
How would you prevent a new workload from ever being built directly on a static IAM user again, at an organizational level rather than case by case?
AdvancedAWS8 min
A third-party application only supports static AWS access keys and can't use an instance profile or role. How do you handle this without abandoning least privilege entirely?
AdvancedAWS8 min
A security scanner just flagged one of your production S3 buckets as publicly readable. Walk through how you'd respond in the first hour and prevent a repeat.
AdvancedAWSS3Security10 min
How would you design alerting so a public S3 exposure is caught within minutes, rather than being discovered by an external scanner or a customer report?
AdvancedAWSS38 min
How would your incident response differ if an exposed S3 bucket allowed public write access, not just public read?
AdvancedAWSS38 min
Should a new AKS cluster use native Kubernetes RBAC or Azure RBAC for Kubernetes Authorization to control kubectl-level access, and what does the Azure option actually change?
IntermediateAzureKubernetesAKS6 min
How would you let a pod in AKS call a Key Vault or Storage API using its own Azure identity, without mounting any credential file or secret into the pod at all?
AdvancedAzureKubernetesAKS7 min
An App Service using Managed Identity to call a storage account worked fine for months. After a Private Endpoint was added to that storage account, the App Service started failing to reach it. Why?
AdvancedAzureApp ServiceBlob Storage7 min
A new Key Vault needs a permission model — should you use Azure RBAC or the older vault access policies, and why does Key Vault even have two separate systems for this?
IntermediateAzureKey Vault6 min
How would you design secret rotation for a live, high-traffic application backed by Key Vault, so rotating a credential never causes a production outage?
ExpertAzureKey Vault8 min
A Function App using Managed Identity to read a Key Vault secret works most of the time, but intermittently fails on startup with an authorization error. How do you actually diagnose this?
AdvancedAzureKey Vault7 min
A CI/CD pipeline that's deployed successfully for two years suddenly fails every run overnight, with no recent pipeline or code changes. How do you diagnose it, and prevent it happening silently again?
IntermediateAzure6 min
A single Azure service connection with subscription-wide Contributor access is used by every pipeline, including ones that only read a storage account. What's wrong here?
AdvancedAzure Pipelines7 min
A storage account's firewall was locked down to specific VNets for security, and now diagnostic logging and a few other first-party Azure integrations silently stopped working. What's actually happening?
AdvancedAzureBlob Storage6 min
A compliance requirement says certain records must be provably unmodifiable for seven years. How would you design this with Blob Storage's immutability features, and what breaks if you choose the wrong policy type?
AdvancedAzureBlob Storage7 min
An app authenticates to Blob Storage using a long-lived SAS token embedded in configuration. Why move it to Managed Identity, and what does a SAS actually give up that Managed Identity doesn't?
IntermediateAzureBlob Storage7 min
What's the trade-off between running security scans as a separate CI job versus as a local pre-commit/pre-push hook?
IntermediateDevSecOps6 min
How would you measure whether engineers are actually acting on security scan findings, versus just dismissing them to unblock their PR?
IntermediateDevSecOps6 min
How would you handle a pre-existing backlog of medium-severity security findings that predates your new scanning rollout, without blocking every team's work on day one?
IntermediateDevSecOps7 min
How would you integrate SAST, dependency scanning, and secrets scanning into a CI/CD pipeline without making every single PR painfully slow?
IntermediateDevSecOps8 min
How would you design artifact signing into your CI/CD pipeline so a deployed container image or binary can be verified as genuinely coming from your build, not tampered with in transit?
AdvancedDevSecOps7 min
Your container scanner reports 200+ vulnerabilities in a base image you didn't choose and can't easily replace. How do you triage this into something actionable?
IntermediateDevSecOpsDocker7 min
What does 'build provenance' actually mean in a supply-chain security context, and how would you start implementing it (e.g. via SLSA) for an existing CI pipeline?
AdvancedDevSecOps8 min