>DevOps Interview KB

Practical Interview Questions — All Categories

131 questions across 30 categories

Hands-on, command-driven questions testing whether you can actually operate these tools, not just discuss them.

How would you audit whether an ECS task role or Lambda execution role is actually scoped tightly, versus just copy-pasted from a broader existing role?

AdvancedAWS7 min

What CloudTrail-based alerting would you specifically set up for a narrowly-scoped static-key IAM user, and how would you tune it to avoid false positives?

AdvancedAWS7 min

How would you design the exception process for an SCP blocking IAM user creation, so legitimate cases aren't blocked indefinitely by bureaucracy?

AdvancedAWS7 min

How would you measure whether an IAM governance change (like an SCP blocking user creation) actually worked, six months later?

IntermediateAWS6 min

How would you design automated credential rotation to handle the overlap window safely, so the application never experiences an auth failure?

AdvancedAWS7 min

What idempotency key design would you use for a payment-related Lambda function, given the higher stakes of a duplicate execution?

AdvancedAWSLambda8 min

Why does Lambda initialization code placed outside the handler function only run once per environment, and how would you use that intentionally?

IntermediateAWSLambda6 min

How would you size Provisioned Concurrency for a Lambda function with a predictable daily peak but otherwise low traffic?

IntermediateAWSLambda6 min

How would you design a synthetic load test to reproduce and measure Lambda's bursty cold-start pattern before it shows up in production?

AdvancedAWSLambda7 min

How would you tune a hedge-request delay so it targets genuine cold-start tail latency without firing on every normal request?

AdvancedAWSLambda7 min

How would you audit all S3 buckets in an account for their current Block Public Access and policy configuration, at scale?

AdvancedAWSS37 min

How would you handle the allowlisting process for intentionally-public S3 buckets so it doesn't become its own source of friction or forgotten debt?

IntermediateAWSS36 min

How would you measure whether an S3 public-exposure alerting system is actually working, short of waiting for a real incident?

IntermediateAWS6 min

What preventive controls would make an S3 public-write exposure incident less damaging in the future — bucket policies, Object Lock, or something else?

IntermediateAWSS36 min