DevSecOps Interview Questions
72 questions across 16 categories
Security integrated into the delivery pipeline — supply chain, secrets management, access control, and shifting security left.
A widely-used open-source dependency your organization relies on is publicly disclosed as compromised — a malicious backdoor was found in a recent release. How do you respond?
ExpertDevSecOps9 min
Your build just pulled in a package from the public npm registry instead of your internal package with the same name, and it wasn't the version your team published. What's happening, and how do you respond?
AdvancedDevSecOps8 min
What's the actual trade-off between pinning exact dependency versions and allowing floating version ranges, from a supply-chain security perspective?
IntermediateDevSecOps6 min
A customer's procurement team now requires an SBOM for every release. How would you design SBOM generation into your build pipeline so it's actually useful, not just a compliance checkbox?
AdvancedDevSecOps8 min
A widely-used third-party GitHub Action your pipelines depend on was compromised via a stolen maintainer token. What's your actual exposure?
AdvancedDevSecOpsGitHub Actions8 min
How would you audit an entire GCP organization to find every principal holding Owner or Editor at the project level, before a security review?
AdvancedGCP7 min
Why is granting a GCP Editor or Owner basic role considered dangerous, and how do predefined and custom roles fix that?
BeginnerGCP6 min
A GCP service account key was accidentally committed to a public repository — walk through your incident response, GCP-specific steps included.
AdvancedGCP8 min
A GKE workload needs to call a GCP API — should it use Workload Identity or a mounted service account key file, and why?
IntermediateGCPGKE7 min
A signed URL was accidentally shared publicly — can you revoke it before it expires, and how would you design around this risk?
AdvancedGCPCloud Storage7 min
A secret was committed several commits ago and has since been rotated, but it's still sitting in the repository's Git history. How do you actually remove it, not just delete it in a new commit?
AdvancedGit7 min
After migrating to OIDC, how would you detect and alert on someone reintroducing a long-lived AWS access key as a GitHub secret?
IntermediateGitHub ActionsAWS7 min
Design a migration from long-lived AWS access keys stored as GitHub Actions secrets to OIDC-based short-lived credentials, for an organization with 40 repositories deploying to production.
AdvancedGitHub ActionsAWSOIDC12 min
How would you scope an OIDC trust policy differently for a GitHub Actions workflow that runs on pull requests versus one that only runs on main?
AdvancedGitHub ActionsAWS8 min
Why is it specifically dangerous to use self-hosted GitHub Actions runners on a public repository, in a way that doesn't apply to a private repository?
AdvancedGitHub Actions7 min
A team wants to auto-merge every Dependabot PR that passes CI, to reduce the toil of manually reviewing hundreds of dependency bumps. What's the actual risk, and how would you design this safely?
AdvancedGitHubDevSecOps8 min
A service accepts GitHub webhook payloads and triggers a deployment based on push events, but doesn't verify where the request actually came from. What's the risk, and how do you fix it?
IntermediateGitHub6 min
How do you make sure a production deployment token stored as a CI/CD variable can only ever be used by pipelines running against your main branch, not a random feature branch?
IntermediateGitLab CI/CD6 min
A compliance requirement mandates that every commit merged into a regulated project be cryptographically signed and traceable to a verified author. How would you enforce this in GitLab?
AdvancedGitLab CI/CD7 min
GitOps means Git is the source of truth for everything deployed, but you obviously can't commit plaintext secrets to Git. How do you actually reconcile this?
AdvancedGitOpsSecurity8 min
Why is mounting the host Docker socket into a build container considered a security risk beyond just the permission-configuration hassle?
IntermediateJenkinsDocker6 min
An admission webhook's failurePolicy is set to Fail — what happens if the webhook itself becomes unavailable, and why might that be the wrong default?
AdvancedKubernetes7 min
A security scan flags the API server's anonymous authentication as enabled — what does that actually expose, and how would you harden it safely?
AdvancedKubernetes7 min
Runtime security tooling alerts that a specific pod is exhibiting behavior consistent with compromise — walk through your immediate containment response.
ExpertKubernetes8 min