Staff / Principal Interview Questions
228 questions across 34 categories
Expert-level and system-design questions — the scope, trade-offs, and organizational reasoning expected at the most senior technical levels.
What does 'build provenance' actually mean in a supply-chain security context, and how would you start implementing it (e.g. via SLSA) for an existing CI pipeline?
AdvancedDevSecOps8 min
A widely-used open-source dependency your organization relies on is publicly disclosed as compromised — a malicious backdoor was found in a recent release. How do you respond?
ExpertDevSecOps9 min
Your build just pulled in a package from the public npm registry instead of your internal package with the same name, and it wasn't the version your team published. What's happening, and how do you respond?
AdvancedDevSecOps8 min
A customer's procurement team now requires an SBOM for every release. How would you design SBOM generation into your build pipeline so it's actually useful, not just a compliance checkbox?
AdvancedDevSecOps8 min
A widely-used third-party GitHub Action your pipelines depend on was compromised via a stolen maintainer token. What's your actual exposure?
AdvancedDevSecOpsGitHub Actions8 min
How would you further reduce a Docker image's size if the runtime still needs native binary dependencies, beyond what a multi-stage build alone achieves?
AdvancedDocker7 min
A container fails to write to a bind-mounted directory with permission denied, even though the host directory has permissive permissions — why?
AdvancedDocker7 min
How would you design volume mounts for a containerized production database, considering both data persistence and backup requirements?
AdvancedDocker7 min
How would you harden a container to run with a read-only root filesystem, given that some part of the application still needs to write to disk somewhere?
AdvancedDocker7 min
Standard Docker volumes are tied to a single host — how would you give containers access to network-backed storage that survives even the host itself being replaced?
AdvancedDocker7 min
A function migrated from Gen 1 to Gen 2 started returning occasionally-wrong results under load — what changed, and how do you fix it?
ExpertGCPCloud Functions8 min
A Cloud Function times out mid-execution after partially completing a multi-step operation — what state does it leave behind, and how do you design around this?
AdvancedGCPCloud Functions7 min
After adding a Serverless VPC Access connector to a Cloud Function, cold starts got noticeably slower — why, and is this avoidable?
AdvancedGCPCloud Functions6 min
How would you audit an entire GCP organization to find every principal holding Owner or Editor at the project level, before a security review?
AdvancedGCP7 min
A GCP service account key was accidentally committed to a public repository — walk through your incident response, GCP-specific steps included.
AdvancedGCP8 min
How would you design a CI/CD pipeline's GCP authentication using service account impersonation instead of a downloaded key, and why is that safer?
AdvancedGCP7 min
How would you design a fast, event-driven alerting system to catch an accidentally-public Cloud Storage bucket within minutes, GCP-native?
ExpertGCPCloud Storage8 min
A bucket scan flags a bucket as publicly readable, but Public Access Prevention shows as enabled — how is that possible, and how do you investigate it?
AdvancedGCPCloud Storage7 min
A signed URL was accidentally shared publicly — can you revoke it before it expires, and how would you design around this risk?
AdvancedGCPCloud Storage7 min
Object versioning was enabled for safety, but a lifecycle rule deleting noncurrent versions caused the same data loss versioning was meant to prevent — how?
AdvancedGCPCloud Storage7 min
A secret was committed several commits ago and has since been rotated, but it's still sitting in the repository's Git history. How do you actually remove it, not just delete it in a new commit?
AdvancedGit7 min
Design a migration from long-lived AWS access keys stored as GitHub Actions secrets to OIDC-based short-lived credentials, for an organization with 40 repositories deploying to production.
AdvancedGitHub ActionsAWSOIDC12 min
How would the OIDC-based deploy design change for a monorepo where multiple independent deploy targets live in one repository?
ExpertGitHub ActionsAWS8 min
How would you scope an OIDC trust policy differently for a GitHub Actions workflow that runs on pull requests versus one that only runs on main?
AdvancedGitHub ActionsAWS8 min