DevSecOps Interview Questions
72 questions across 16 categories
Security integrated into the delivery pipeline — supply chain, secrets management, access control, and shifting security left.
An admission webhook's failurePolicy is set to Fail — what happens if the webhook itself becomes unavailable, and why might that be the wrong default?
AdvancedKubernetes7 min
A security scan flags the API server's anonymous authentication as enabled — what does that actually expose, and how would you harden it safely?
AdvancedKubernetes7 min
Runtime security tooling alerts that a specific pod is exhibiting behavior consistent with compromise — walk through your immediate containment response.
ExpertKubernetes8 min
How would you design a policy requiring every image deployed to a cluster be cryptographically signed, and what does that actually protect against?
ExpertKubernetes8 min
A security scan found the kubelet's API port reachable without authentication on some nodes — what can an attacker actually do with that, and how do you fix it?
ExpertKubernetes8 min
A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?
AdvancedKubernetes7 min
What's the difference between mounting a Secret as a volume versus injecting it as an environment variable, from a security perspective?
IntermediateKubernetes6 min
Why are Kubernetes Secrets only base64-encoded by default, not encrypted, and how would you actually protect them at rest?
BeginnerKubernetes5 min
A security team rejects a pod spec requesting privileged: true — what SecurityContext alternatives would you propose to meet the actual requirement?
AdvancedKubernetes7 min
How would you audit an entire cluster to find ServiceAccounts with effectively cluster-admin permissions before a security review?
AdvancedKubernetes7 min
A pod's ServiceAccount token was found in a public repo — what's your incident response, and how do you reduce blast radius for next time?
ExpertKubernetes8 min
A Pod Security Standard (restricted) rejects a legacy workload that needs to run as root — how do you handle this without disabling the standard cluster-wide?
AdvancedKubernetes7 min
A team deletes a PVC expecting the data gone, but it's later recovered from the underlying disk — why, and how should reclaim policy be chosen deliberately?
IntermediateKubernetes6 min