>DevOps Interview KB

Security Interview Questions — All Categories

49 questions across 15 categories

Security-focused questions spanning IAM, secrets management, supply chain, and access control across every technology in the corpus.

Design a migration from long-lived AWS access keys stored as GitHub Actions secrets to OIDC-based short-lived credentials, for an organization with 40 repositories deploying to production.

AdvancedGitHub ActionsAWSOIDC12 min

How would you scope an OIDC trust policy differently for a GitHub Actions workflow that runs on pull requests versus one that only runs on main?

AdvancedGitHub ActionsAWS8 min

Why is it specifically dangerous to use self-hosted GitHub Actions runners on a public repository, in a way that doesn't apply to a private repository?

AdvancedGitHub Actions7 min

A team wants to auto-merge every Dependabot PR that passes CI, to reduce the toil of manually reviewing hundreds of dependency bumps. What's the actual risk, and how would you design this safely?

AdvancedGitHubDevSecOps8 min

A service accepts GitHub webhook payloads and triggers a deployment based on push events, but doesn't verify where the request actually came from. What's the risk, and how do you fix it?

IntermediateGitHub6 min

How do you make sure a production deployment token stored as a CI/CD variable can only ever be used by pipelines running against your main branch, not a random feature branch?

IntermediateGitLab CI/CD6 min

A compliance requirement mandates that every commit merged into a regulated project be cryptographically signed and traceable to a verified author. How would you enforce this in GitLab?

AdvancedGitLab CI/CD7 min

GitOps means Git is the source of truth for everything deployed, but you obviously can't commit plaintext secrets to Git. How do you actually reconcile this?

AdvancedGitOpsSecurity8 min

Why is mounting the host Docker socket into a build container considered a security risk beyond just the permission-configuration hassle?

IntermediateJenkinsDocker6 min

An admission webhook's failurePolicy is set to Fail — what happens if the webhook itself becomes unavailable, and why might that be the wrong default?

AdvancedKubernetes7 min

A security scan flags the API server's anonymous authentication as enabled — what does that actually expose, and how would you harden it safely?

AdvancedKubernetes7 min

Runtime security tooling alerts that a specific pod is exhibiting behavior consistent with compromise — walk through your immediate containment response.

ExpertKubernetes8 min

How would you design a policy requiring every image deployed to a cluster be cryptographically signed, and what does that actually protect against?

ExpertKubernetes8 min

A security scan found the kubelet's API port reachable without authentication on some nodes — what can an attacker actually do with that, and how do you fix it?

ExpertKubernetes8 min

A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?

AdvancedKubernetes7 min

What's the difference between mounting a Secret as a volume versus injecting it as an environment variable, from a security perspective?

IntermediateKubernetes6 min

Why are Kubernetes Secrets only base64-encoded by default, not encrypted, and how would you actually protect them at rest?

BeginnerKubernetes5 min

A security team rejects a pod spec requesting privileged: true — what SecurityContext alternatives would you propose to meet the actual requirement?

AdvancedKubernetes7 min

How would you audit an entire cluster to find ServiceAccounts with effectively cluster-admin permissions before a security review?

AdvancedKubernetes7 min

A pod's ServiceAccount token was found in a public repo — what's your incident response, and how do you reduce blast radius for next time?

ExpertKubernetes8 min

A Pod Security Standard (restricted) rejects a legacy workload that needs to run as root — how do you handle this without disabling the standard cluster-wide?

AdvancedKubernetes7 min

A team deletes a PVC expecting the data gone, but it's later recovered from the underlying disk — why, and how should reclaim policy be chosen deliberately?

IntermediateKubernetes6 min

A Python automation script uses subprocess.run(f'kubectl get pod {pod_name}', shell=True) where pod_name comes from user input. What's actually wrong with this, and how do you fix it?

AdvancedPython7 min

A developer just committed a live database password directly into a public GitHub repository. It's been merged and pushed. What do you do, in order?

AdvancedSecurityGitHub10 min