>DevOps Interview KB

DevSecOps Interview Questions

72 questions across 16 categories

Security integrated into the delivery pipeline — supply chain, secrets management, access control, and shifting security left.

How would you design a policy requiring every image deployed to a cluster be cryptographically signed, and what does that actually protect against?

ExpertKubernetes8 min

A security scan found the kubelet's API port reachable without authentication on some nodes — what can an attacker actually do with that, and how do you fix it?

ExpertKubernetes8 min

A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?

AdvancedKubernetes7 min

What's the difference between mounting a Secret as a volume versus injecting it as an environment variable, from a security perspective?

IntermediateKubernetes6 min

Why are Kubernetes Secrets only base64-encoded by default, not encrypted, and how would you actually protect them at rest?

BeginnerKubernetes5 min

A security team rejects a pod spec requesting privileged: true — what SecurityContext alternatives would you propose to meet the actual requirement?

AdvancedKubernetes7 min

How would you audit an entire cluster to find ServiceAccounts with effectively cluster-admin permissions before a security review?

AdvancedKubernetes7 min

A pod's ServiceAccount token was found in a public repo — what's your incident response, and how do you reduce blast radius for next time?

ExpertKubernetes8 min

A Pod Security Standard (restricted) rejects a legacy workload that needs to run as root — how do you handle this without disabling the standard cluster-wide?

AdvancedKubernetes7 min

A team deletes a PVC expecting the data gone, but it's later recovered from the underlying disk — why, and how should reclaim policy be chosen deliberately?

IntermediateKubernetes6 min

A Python automation script uses subprocess.run(f'kubectl get pod {pod_name}', shell=True) where pod_name comes from user input. What's actually wrong with this, and how do you fix it?

AdvancedPython7 min

How would you design a recurring privileged-access review that catches stale access at scale without becoming a rubber-stamp exercise nobody takes seriously?

AdvancedSecurity7 min

How would you design a 'break-glass' emergency access process that lets an engineer bypass normal approval during a critical incident, without that becoming a permanent backdoor around your access controls?

ExpertSecurity8 min

You're designing the IAM/role structure for a shared platform used by 12 different teams. How do you avoid both 'everyone is admin' and a role-request bottleneck that blocks every team on you?

AdvancedSecurity8 min

When would you actually choose manual credential rotation over fully automated rotation, given that automation is generally considered the more secure default?

IntermediateSecurity6 min

A security audit finds 340 service accounts, and nobody can say for certain which ones are still in use. How do you find and safely remove the dead ones without breaking production?

AdvancedSecurity8 min

A critical production system is accessed via one shared 'admin' account used by six engineers, with no individual audit trail. How do you fix this?

IntermediateSecurity7 min

After a change to your SSO/identity provider configuration, nobody — including admins — can log into any connected system. How do you get back in, and how do you diagnose the actual cause?

AdvancedSecurity8 min

A third-party vendor's contract is up for renewal, and their integration still has the broad access it was granted two years ago during initial setup. How do you review and right-size it before renewing?

IntermediateSecurity7 min

How would you design credential architecture so a hardcoded secret, if it happens again, has a much smaller blast radius?

AdvancedSecurity8 min

A developer just committed a live database password directly into a public GitHub repository. It's been merged and pushed. What do you do, in order?

AdvancedSecurityGitHub10 min

How would your incident response to a hardcoded secret committed to a repository differ if the repository were private rather than public?

IntermediateGit6 min

What's the trade-off between rewriting Git history to remove a committed secret versus simply rotating it and leaving the now-worthless value in history?

IntermediateGit6 min

A database password is passed as a resource argument in Terraform — does marking the variable sensitive actually protect it in the state file?

AdvancedTerraform7 min