>DevOps Interview KB

Security Interview Questions — All Categories

16 questions tagged with Security as a technology, across every category it appears in

A security scanner just flagged one of your production S3 buckets as publicly readable. Walk through how you'd respond in the first hour and prevent a repeat.

AdvancedAWSS3Security10 min

Design a migration from long-lived AWS access keys stored as GitHub Actions secrets to OIDC-based short-lived credentials, for an organization with 40 repositories deploying to production.

AdvancedGitHub ActionsAWSOIDC12 min

GitOps means Git is the source of truth for everything deployed, but you obviously can't commit plaintext secrets to Git. How do you actually reconcile this?

AdvancedGitOpsSecurity8 min

Should TLS terminate at the load balancer, or should encrypted traffic pass all the way through to the backend servers? What's the actual security and operational trade-off?

IntermediateNetworkingSecurity7 min

You find a piece of a legacy pipeline that seems actively dangerous — overly broad credentials, say — but nobody can explain why it's configured that way. What do you do?

AdvancedSecurity7 min

How would you design a recurring privileged-access review that catches stale access at scale without becoming a rubber-stamp exercise nobody takes seriously?

AdvancedSecurity7 min

How would you design a 'break-glass' emergency access process that lets an engineer bypass normal approval during a critical incident, without that becoming a permanent backdoor around your access controls?

ExpertSecurity8 min

You're designing the IAM/role structure for a shared platform used by 12 different teams. How do you avoid both 'everyone is admin' and a role-request bottleneck that blocks every team on you?

AdvancedSecurity8 min

When would you actually choose manual credential rotation over fully automated rotation, given that automation is generally considered the more secure default?

IntermediateSecurity6 min

A security audit finds 340 service accounts, and nobody can say for certain which ones are still in use. How do you find and safely remove the dead ones without breaking production?

AdvancedSecurity8 min

A critical production system is accessed via one shared 'admin' account used by six engineers, with no individual audit trail. How do you fix this?

IntermediateSecurity7 min

After a change to your SSO/identity provider configuration, nobody — including admins — can log into any connected system. How do you get back in, and how do you diagnose the actual cause?

AdvancedSecurity8 min

A third-party vendor's contract is up for renewal, and their integration still has the broad access it was granted two years ago during initial setup. How do you review and right-size it before renewing?

IntermediateSecurity7 min

How would you design credential architecture so a hardcoded secret, if it happens again, has a much smaller blast radius?

AdvancedSecurity8 min

A developer just committed a live database password directly into a public GitHub repository. It's been merged and pushed. What do you do, in order?

AdvancedSecurityGitHub10 min

Design a centralized secrets management system for an org currently scattering credentials across env vars, config files, and CI/CD tool stores, with no consistent rotation or audit trail.

ExpertSecurityDevSecOps14 min