Quiz
2667 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2667
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture86
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture88
Streaming & Real-Time Data93
Data Governance & Semantics81
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk88
66 questions in Security Architecture.
-
Secrets Management advanced
A CI/CD platform runs untrusted code from external contributors and also holds deployment credentials. How should secrets be architected so a malicious pull request cannot exfiltrate them?
2 min answer secretsci-cduntrusted-codescoping -
Secrets Management advanced
An estate has database passwords in environment variables across 200 services. Design the migration to a secrets manager.
2 min answer secretsmigrationworkload-identityrotation -
Secrets Management advanced
You deploy a secrets manager. Every application now fetches its secrets from it. Security asks how the applications authenticate to the vault. What is the answer?
2 min answer secretsbootstrappingidentity -
Secure API Design advanced
A marketplace API is used by sellers, buyers, internal services and third-party tools. Which security properties must be enforced at the API layer, and which must not be?
2 min answer api-securityauthorizationrate-limitingenumeration -
Secure API Design advanced
How would you make it structurally impossible for a developer to add an endpoint that returns another tenant's data?
2 min answer multi-tenancyisolationauthorisationstructure -
Secure API Design advanced
In March 2023 OpenAI disclosed that a bug in the redis-py async client let one request receive data left behind in a recycled connection, so some users saw other users' chat titles and some payment details. The authorisation code was not at fault. Which class of control was missing, and what would you change?
3 min answer openaiconnection-poolmulti-tenancyrequest-scoped-identity -
Secure API Design advanced
Review this design. Every one of 40 API endpoints checks that the caller owns the requested resource by fetching it and comparing an owner field in the controller. A penetration test found one endpoint missing the check. What would you change and what would you leave alone?
3 min answer authorizationbolaidorapi security -
Secure API Design advanced
You are reviewing a new public API before launch. What do you check, in priority order?
2 min answer api-securityowaspreviewauthorization -
Security Architecture advanced
An enterprise platform's security review produces hundreds of findings across dozens of systems, and remediation capacity cannot keep up. What is structurally wrong, and what changes?
2 min answer security-architecturepreventive-controlsscaleenterprise -
Security Architecture advanced
Equifax was breached in 2017 through a vulnerability with a patch available two months earlier. Beyond "patch faster", what architectural and governance failures does that imply?
2 min answer complianceprivacyvulnerability-managementcase-study -
Security Architecture advanced
The 2019 Capital One breach chained a server-side request forgery to an over-permissive IAM role. Walk the chain, and say which single control would have contained it.
2 min answer ssrfiamleast-privilegecloud -
Security Architecture advanced
Your services currently trust anything inside the VPC. A security review says move to zero trust. What changes, and what will it cost you?
2 min answer zero-trustmtlsidentitysecurity