Quiz
2707 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2707
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture96
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture98
Streaming & Real-Time Data93
Data Governance & Semantics91
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk98
74 questions in Regulatory & Data Protection Architecture.
-
Data Residency advanced
An e-commerce group of Flipkart's shape runs an in-India cell for regulated payment data and an EU cell for everything else. A quarterly control test samples 500 rows from the EU warehouse and finds 38 carrying Indian cardholder identifiers. The routing layer is correct and the replication topology is correct. Where do you look and in what order?
3 min answer data-residencytelemetry-leakagedata-classificationegress-control -
Data Residency advanced
Six weeks before launch, legal confirms that customer data for one market must be processed and stored in-country. The architecture is single-region in another jurisdiction. What do you do?
3 min answer residencyregulatoryarchitecturemigration -
Data Subject Rights advanced
Design the architecture for handling access, correction and erasure requests across a large estate.
1 min answer dsarerasurediscoveryorchestration -
Data Subject Rights advanced
You receive a subject access request. Legal says you have 30 days to produce everything you hold about this person. What does your architecture need to make that possible?
2 min answer gdprprivacyarchitecture -
Data Subject Rights advanced
Your organisation receives its first subject access request. Nobody knows where the person's data is. How do you respond within thirty days?
2 min answer privacydsardiscoveryprocess -
Digital Sovereignty advanced
A customer requires data sovereignty. What three questions do you ask before designing anything?
2 min answer sovereigntyresidencyaccessexit -
Digital Sovereignty advanced
A government customer requires that no foreign entity can access their data or compel its disclosure. What are the options and what does each cost?
1 min answer sovereigntyjurisdictionencryptionoperations -
Digital Sovereignty advanced
A public-sector customer will only accept a sovereign cloud region operated under local control. The team has treated it as a change of deployment target. What has the business actually bought and what is the bill?
2 min answer sovereigntysovereign-cloudportabilitydivergence -
Digital Sovereignty advanced
Review this claim. A public-sector tenant is served from an in-country region of a global cloud, staffed locally, with customer-managed keys in the provider's key service and a contract forbidding foreign access. The CI pipeline, the identity provider, the observability backend and the provider's operator tooling all run outside the jurisdiction. The team calls this sovereign. What would you remove, what would you change, and what would you leave alone?
2 min answer digital-sovereigntyexternal-key-storecontrol-planekey-custody -
Erasure vs Immutability advanced
A brokerage must keep an immutable audit trail and honour erasure requests. How can both be true?
2 min answer growwerasureimmutabilitypseudonymisation -
Erasure vs Immutability advanced
A marketplace of eBay's shape has an append-only event log of roughly 8 billion events over six years with personal data inline in the payloads. A new erasure obligation lands and crypto-shredding is the chosen answer, but no per-subject keys exist yet. Sequence the migration under live traffic and name the point of no return.
3 min answer crypto-shreddingevent-sourcingenvelope-encryptionobject-lock -
Erasure vs Immutability advanced
An event-sourced system keeps an immutable log. A subject requests erasure. How is this resolved?
1 min answer erasureimmutabilityevent-sourcingcrypto-shredding