Quiz
2627 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2627
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture77
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture85
Cost Architecture & FinOps82
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization82
AI-Era Architecture86
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture88
Streaming & Real-Time Data93
Data Governance & Semantics81
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk88
63 questions in Security Architecture.
-
Authorization advanced
An internal API accepts a customer ID and returns that customer's data. It authenticates the calling service with mTLS. What is the flaw?
2 min answer authorizationconfused-deputyzero-trust -
Compliance Frameworks advanced
How would you reduce PCI DSS scope for an e-commerce platform, and what does it cost you?
2 min answer pcicompliancescope-reductiontokenisation -
Compliance Frameworks advanced
PCI DSS assessment covers 40 systems and costs a fortune annually. How would you reduce that architecturally?
2 min answer pciscopetokenisationcompliance -
Encryption advanced
A file storage platform encrypts data at rest and in transit. A customer asks whether the provider can read their files. What does the honest answer depend on, and what would change it?
2 min answer encryptionkey-managementend-to-endthreat-model -
Identity & Access Management advanced
A workforce platform holds identity, payroll and device management, and integrates with dozens of downstream systems. What is the central security risk and how is it bounded?
2 min answer ripplingdeelprivilegeintegrations -
Identity & Access Management advanced
An enterprise platform's permission model has grown to thousands of roles and profiles, and nobody can determine what access a given user actually has. What is the diagnosis and the remediation?
2 min answer iamrbacabacleast-privilege -
Identity & Access Management advanced
Design the break-glass access mechanism for production. What are the requirements?
2 min answer accessincidentcontrols -
Security Incident Response advanced
A blockchain infrastructure provider suspects a compromised credential with access to production. What must the response prioritise, and what capability determines how well it goes?
2 min answer polygonincident-responsecontainmentforensics -
Security Incident Response advanced
A platform discovers that an attacker has held valid credentials for an unknown period. What does the response require beyond containment, and what determines how well it goes?
2 min answer incident-responseforensicscredentialsdisclosure -
Security Incident Response advanced
Anomalous access to a customer database is detected. Walk me through the first day, and say what determines whether you can answer the regulator.
2 min answer incident-responsebreachforensicsnotification -
Security Incident Response advanced
You discover an attacker holds valid credentials in your environment. What are your first three actions and what must already exist for them to be possible?
2 min answer incident-responsecontainmentforensicscredentials -
Key Management advanced
A communication platform adds end-to-end encryption to multi-party meetings. What are the hard problems, and which are cryptographic versus operational?
2 min answer key-managemente2eegroup-keystrust