>DevOps Interview KB

DevSecOps Interview Questions

72 questions across 16 categories

Security integrated into the delivery pipeline — supply chain, secrets management, access control, and shifting security left.

An admission webhook's failurePolicy is set to Fail — what happens if the webhook itself becomes unavailable, and why might that be the wrong default?

AdvancedKubernetes7 min

A security scan flags the API server's anonymous authentication as enabled — what does that actually expose, and how would you harden it safely?

AdvancedKubernetes7 min

Runtime security tooling alerts that a specific pod is exhibiting behavior consistent with compromise — walk through your immediate containment response.

ExpertKubernetes8 min

How would you design a policy requiring every image deployed to a cluster be cryptographically signed, and what does that actually protect against?

ExpertKubernetes8 min

A security scan found the kubelet's API port reachable without authentication on some nodes — what can an attacker actually do with that, and how do you fix it?

ExpertKubernetes8 min

A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?

AdvancedKubernetes7 min

What's the difference between mounting a Secret as a volume versus injecting it as an environment variable, from a security perspective?

IntermediateKubernetes6 min

Why are Kubernetes Secrets only base64-encoded by default, not encrypted, and how would you actually protect them at rest?

BeginnerKubernetes5 min

A security team rejects a pod spec requesting privileged: true — what SecurityContext alternatives would you propose to meet the actual requirement?

AdvancedKubernetes7 min

How would you audit an entire cluster to find ServiceAccounts with effectively cluster-admin permissions before a security review?

AdvancedKubernetes7 min

A pod's ServiceAccount token was found in a public repo — what's your incident response, and how do you reduce blast radius for next time?

ExpertKubernetes8 min

A Pod Security Standard (restricted) rejects a legacy workload that needs to run as root — how do you handle this without disabling the standard cluster-wide?

AdvancedKubernetes7 min

A team deletes a PVC expecting the data gone, but it's later recovered from the underlying disk — why, and how should reclaim policy be chosen deliberately?

IntermediateKubernetes6 min