DevSecOps Interview Questions
72 questions across 16 categories
Security integrated into the delivery pipeline — supply chain, secrets management, access control, and shifting security left.
You inherit an EC2 workload that authenticates to AWS using an IAM user with AdministratorAccess. How would you migrate it to least-privilege access without causing an outage?
AdvancedAWSIAMEC212 min
How would you prevent a new workload from ever being built directly on a static IAM user again, at an organizational level rather than case by case?
AdvancedAWS8 min
A third-party application only supports static AWS access keys and can't use an instance profile or role. How do you handle this without abandoning least privilege entirely?
AdvancedAWS8 min
A security scanner just flagged one of your production S3 buckets as publicly readable. Walk through how you'd respond in the first hour and prevent a repeat.
AdvancedAWSS3Security10 min
How would you design alerting so a public S3 exposure is caught within minutes, rather than being discovered by an external scanner or a customer report?
AdvancedAWSS38 min
How would your incident response differ if an exposed S3 bucket allowed public write access, not just public read?
AdvancedAWSS38 min