Practical Interview Questions — All Categories
131 questions across 30 categories
Hands-on, command-driven questions testing whether you can actually operate these tools, not just discuss them.
How would you audit an existing large Ansible playbook to find all the places check mode's coverage is actually incomplete?
AdvancedAnsible7 min
How would you build confidence in a playbook's check-mode output when it has to use command/shell for something with no equivalent module?
AdvancedAnsible7 min
How would you retrofit idempotency checks into an existing large Ansible playbook full of command/shell tasks, without rewriting every task at once?
AdvancedAnsible8 min
How would you verify a purpose-built module replacement produces the exact same end state as the shell command it replaced, in a repeatable way?
AdvancedAnsible7 min
How would you distinguish 'the migration itself is broken' from 'this was a transient failure worth retrying,' in terms of alerting design?
AdvancedArgo CD7 min
How would you clean up old, hash-named Argo CD migration Jobs so they don't accumulate indefinitely in the cluster?
IntermediateArgo CDKubernetes6 min
How do you control the order Argo CD applies resources within a single Application, e.g. making sure a database migration Job completes before the Deployment that depends on it rolls out?
AdvancedArgo CDKubernetes8 min
How would you handle an Argo CD migration Job that should run on every sync versus one that should only run when the migration itself actually changed?
AdvancedArgo CDKubernetes7 min
How does Argo CD's syncPolicy.retry backoff configuration work, and how would you tune it for a slow-starting dependency?
IntermediateArgo CD6 min
How would you verify a Helm chart's hooks behave correctly under Argo CD before migrating a production chart from helm install to GitOps?
AdvancedArgo CDHelm7 min
How would you audit whether an ECS task role or Lambda execution role is actually scoped tightly, versus just copy-pasted from a broader existing role?
AdvancedAWS7 min
What CloudTrail-based alerting would you specifically set up for a narrowly-scoped static-key IAM user, and how would you tune it to avoid false positives?
AdvancedAWS7 min
How would you design the exception process for an SCP blocking IAM user creation, so legitimate cases aren't blocked indefinitely by bureaucracy?
AdvancedAWS7 min
How would you measure whether an IAM governance change (like an SCP blocking user creation) actually worked, six months later?
IntermediateAWS6 min
How would you design automated credential rotation to handle the overlap window safely, so the application never experiences an auth failure?
AdvancedAWS7 min
What idempotency key design would you use for a payment-related Lambda function, given the higher stakes of a duplicate execution?
AdvancedAWSLambda8 min
Why does Lambda initialization code placed outside the handler function only run once per environment, and how would you use that intentionally?
IntermediateAWSLambda6 min
How would you size Provisioned Concurrency for a Lambda function with a predictable daily peak but otherwise low traffic?
IntermediateAWSLambda6 min
How would you design a synthetic load test to reproduce and measure Lambda's bursty cold-start pattern before it shows up in production?
AdvancedAWSLambda7 min
How would you tune a hedge-request delay so it targets genuine cold-start tail latency without firing on every normal request?
AdvancedAWSLambda7 min
How would you audit all S3 buckets in an account for their current Block Public Access and policy configuration, at scale?
AdvancedAWSS37 min
How would you handle the allowlisting process for intentionally-public S3 buckets so it doesn't become its own source of friction or forgotten debt?
IntermediateAWSS36 min
How would you measure whether an S3 public-exposure alerting system is actually working, short of waiting for a real incident?
IntermediateAWS6 min
What preventive controls would make an S3 public-write exposure incident less damaging in the future — bucket policies, Object Lock, or something else?
IntermediateAWSS36 min