>DevOps Interview KB

Security Interview Questions — All Categories

49 questions across 15 categories

Security-focused questions spanning IAM, secrets management, supply chain, and access control across every technology in the corpus.

You inherit an EC2 workload that authenticates to AWS using an IAM user with AdministratorAccess. How would you migrate it to least-privilege access without causing an outage?

AdvancedAWSIAMEC212 min

How would you prevent a new workload from ever being built directly on a static IAM user again, at an organizational level rather than case by case?

AdvancedAWS8 min

A third-party application only supports static AWS access keys and can't use an instance profile or role. How do you handle this without abandoning least privilege entirely?

AdvancedAWS8 min

A security scanner just flagged one of your production S3 buckets as publicly readable. Walk through how you'd respond in the first hour and prevent a repeat.

AdvancedAWSS3Security10 min

How would you design alerting so a public S3 exposure is caught within minutes, rather than being discovered by an external scanner or a customer report?

AdvancedAWSS38 min

How would your incident response differ if an exposed S3 bucket allowed public write access, not just public read?

AdvancedAWSS38 min

Should a new AKS cluster use native Kubernetes RBAC or Azure RBAC for Kubernetes Authorization to control kubectl-level access, and what does the Azure option actually change?

IntermediateAzureKubernetesAKS6 min

How would you let a pod in AKS call a Key Vault or Storage API using its own Azure identity, without mounting any credential file or secret into the pod at all?

AdvancedAzureKubernetesAKS7 min

An App Service using Managed Identity to call a storage account worked fine for months. After a Private Endpoint was added to that storage account, the App Service started failing to reach it. Why?

AdvancedAzureApp ServiceBlob Storage7 min

A new Key Vault needs a permission model — should you use Azure RBAC or the older vault access policies, and why does Key Vault even have two separate systems for this?

IntermediateAzureKey Vault6 min

How would you design secret rotation for a live, high-traffic application backed by Key Vault, so rotating a credential never causes a production outage?

ExpertAzureKey Vault8 min

A Function App using Managed Identity to read a Key Vault secret works most of the time, but intermittently fails on startup with an authorization error. How do you actually diagnose this?

AdvancedAzureKey Vault7 min

A CI/CD pipeline that's deployed successfully for two years suddenly fails every run overnight, with no recent pipeline or code changes. How do you diagnose it, and prevent it happening silently again?

IntermediateAzure6 min

A single Azure service connection with subscription-wide Contributor access is used by every pipeline, including ones that only read a storage account. What's wrong here?

AdvancedAzure Pipelines7 min

A storage account's firewall was locked down to specific VNets for security, and now diagnostic logging and a few other first-party Azure integrations silently stopped working. What's actually happening?

AdvancedAzureBlob Storage6 min

A compliance requirement says certain records must be provably unmodifiable for seven years. How would you design this with Blob Storage's immutability features, and what breaks if you choose the wrong policy type?

AdvancedAzureBlob Storage7 min

An app authenticates to Blob Storage using a long-lived SAS token embedded in configuration. Why move it to Managed Identity, and what does a SAS actually give up that Managed Identity doesn't?

IntermediateAzureBlob Storage7 min

How would you audit an entire GCP organization to find every principal holding Owner or Editor at the project level, before a security review?

AdvancedGCP7 min

Why is granting a GCP Editor or Owner basic role considered dangerous, and how do predefined and custom roles fix that?

BeginnerGCP6 min

A GCP service account key was accidentally committed to a public repository — walk through your incident response, GCP-specific steps included.

AdvancedGCP8 min

A GKE workload needs to call a GCP API — should it use Workload Identity or a mounted service account key file, and why?

IntermediateGCPGKE7 min

A signed URL was accidentally shared publicly — can you revoke it before it expires, and how would you design around this risk?

AdvancedGCPCloud Storage7 min

A secret was committed several commits ago and has since been rotated, but it's still sitting in the repository's Git history. How do you actually remove it, not just delete it in a new commit?

AdvancedGit7 min

After migrating to OIDC, how would you detect and alert on someone reintroducing a long-lived AWS access key as a GitHub secret?

IntermediateGitHub ActionsAWS7 min