Quiz
2667 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2667
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture86
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture88
Streaming & Real-Time Data93
Data Governance & Semantics81
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk88
66 questions in Security Architecture.
-
Key Management advanced
A crypto exchange must hold customer assets while remaining operationally usable. How should key custody, signing, approval and monitoring be architected?
2 min answer coindcxcustodyhsmsegregation -
Key Management advanced
A pipeline writes 200 million objects a day and the security review requires per-object encryption with a managed key service. Roughly how many calls to that service does the naive design make, what does it cost, and what changes the answer by two orders of magnitude?
3 min answer envelope encryptionkmsdata keysthroughput -
Key Management advanced
In a multi-tenant SaaS, would you use one data encryption key for all tenants or one per tenant? Justify.
2 min answer encryptiontenancyerasure -
Network Security advanced
All outbound traffic from a cluster passes through an egress proxy that enforces allowlists and TLS inspection. The proxy does not fail; it gets slow, with p99 rising from 20 ms to 6 s. What happens across the platform over the next ten minutes?
3 min answer egressproxythread exhaustiontimeouts -
Network Security advanced
You propose egress filtering. Engineering says it will break builds and slow delivery. How do you proceed?
2 min answer network-securityexfiltrationadoption -
OAuth 2.0 & OIDC advanced
A developer platform issues OAuth tokens to third-party applications. What scope design decisions determine whether the platform can be operated safely long term?
2 min answer oauthscopesleast-privilegethird-party -
OAuth 2.0 & OIDC advanced
A single-page app has used the OAuth implicit flow since 2017 and keeps the access token in localStorage. Security wants authorization code with PKCE behind a backend-for-frontend holding a cookie session. 180000 daily users and 40 third-party embeds must not be logged out. Sequence the migration.
3 min answer oauthpkcebackend-for-frontendmigration -
OWASP Risks advanced
Broken access control is consistently the top application security risk. Which architectural decisions make it structurally less likely rather than relying on review?
2 min answer access-controlowaspstructureauthorisation -
Privacy Engineering advanced
A consumer platform with 40 million accounts receives about 600 subject access requests a month. Honouring one means assembling a person's data from 23 services that each own their own store. Estimate what the manual path costs and say what changes the number by an order of magnitude.
3 min answer dsargdprsubject-indexdata-lineage -
Privacy Engineering advanced
A discovery platform builds personalisation from user behaviour. What privacy-engineering decisions must be made early, and which are expensive to retrofit?
2 min answer privacydata-minimisationpurpose-limitationdeletion -
Privacy Engineering advanced
Design the mechanism by which a deletion request propagates through a system with a warehouse, a search index, backups and three third-party processors.
2 min answer privacydeletiongdprpropagation -
Privacy Engineering advanced
Product wants to add "customers who bought this also bought" using purchase history. What does privacy by design require here?
2 min answer privacypurpose-limitationminimisationgdpr