Scenario Interview Questions — All Categories
92 questions across 28 categories
Open-ended, realistic situations that combine multiple technologies and force genuine engineering judgment.
Joining a company with none of DevOps, SRE, or Platform Engineering formalized, which would you introduce first, and why?
IntermediateDevops7 min
How would you handle a pre-existing backlog of medium-severity security findings that predates your new scanning rollout, without blocking every team's work on day one?
IntermediateDevSecOps7 min
How would you integrate SAST, dependency scanning, and secrets scanning into a CI/CD pipeline without making every single PR painfully slow?
IntermediateDevSecOps8 min
Your container scanner reports 200+ vulnerabilities in a base image you didn't choose and can't easily replace. How do you triage this into something actionable?
IntermediateDevSecOpsDocker7 min
A GCP service account key was accidentally committed to a public repository — walk through your incident response, GCP-specific steps included.
AdvancedGCP8 min
A signed URL was accidentally shared publicly — can you revoke it before it expires, and how would you design around this risk?
AdvancedGCPCloud Storage7 min
Object versioning was enabled for safety, but a lifecycle rule deleting noncurrent versions caused the same data loss versioning was meant to prevent — how?
AdvancedGCPCloud Storage7 min
Design a migration from long-lived AWS access keys stored as GitHub Actions secrets to OIDC-based short-lived credentials, for an organization with 40 repositories deploying to production.
AdvancedGitHub ActionsAWSOIDC12 min
Your org requires branch protection on main everywhere, but a critical tool has just one maintainer who finds required review genuinely slows down urgent fixes. How do you balance this?
IntermediateGitHub6 min
How would you structure GitLab protected branch rules differently for a fast-moving startup versus a regulated environment requiring strict change control?
IntermediateGitLab6 min
A mutating webhook injects configuration into your resources. When should that injected config actually be tracked in Git instead of ignored via ignoreDifferences?
AdvancedArgo CDKubernetes7 min
You've inherited 60 Jenkins freestyle jobs with configuration nobody fully documented. How would you migrate them to pipeline-as-code without breaking builds teams depend on daily?
IntermediateJenkins7 min
A new mutating webhook accidentally intercepted kube-system pod creation and broke core cluster components — how would you design its scoping to prevent this?
AdvancedKubernetes7 min
Every pod creation cluster-wide suddenly starts failing with an admission webhook TLS error — what happened, and how do you recover quickly?
ExpertKubernetes8 min
An admission webhook's failurePolicy is set to Fail — what happens if the webhook itself becomes unavailable, and why might that be the wrong default?
AdvancedKubernetes7 min
How would you design multi-cluster architecture — when does an org actually need multiple clusters instead of namespaces?
AdvancedKubernetes8 min
A cluster upgrade needs zero workload downtime — walk through sequencing control-plane and node upgrades safely.
AdvancedKubernetes8 min
A team wants to run HPA and VPA on the same Deployment for both CPU and memory — what breaks if you're not careful, and how do you combine them safely?
ExpertKubernetes8 min
A Deployment's pods get evicted during scale-up because new nodes take too long to become ready — how would you close that gap?
ExpertKubernetes8 min
How would you design autoscaling for a workload with a sharp, predictable daily spike versus one with genuinely unpredictable bursty traffic?
AdvancedKubernetes7 min
Runtime security tooling alerts that a specific pod is exhibiting behavior consistent with compromise — walk through your immediate containment response.
ExpertKubernetes8 min
A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?
AdvancedKubernetes7 min
A CRD needs a breaking schema change, but existing custom resources and consumers depend on the old shape — how do you version a CRD safely?
ExpertKubernetes8 min
A team wants to automate a repetitive operational task with a custom Kubernetes operator — when is that actually the right tool versus overkill?
AdvancedKubernetes7 min