Quiz
2741 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2741
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience99
Observability92
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture96
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture102
Data Platform Architecture98
Streaming & Real-Time Data93
Data Governance & Semantics91
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk98
74 questions in Regulatory & Data Protection Architecture.
-
Privacy by Design advanced
On 20 March 2023 a change to OpenAI's servers spiked Redis request cancellations, a redis-py bug returned another user's cached reply on a pooled connection, and chat titles plus payment details of roughly 1.2% of active ChatGPT Plus subscribers were exposed during a nine-hour window. Which design decision turned a client-library bug into a personal-data breach?
3 min answer openaicacheconnection-poolbreach -
Privacy by Design advanced
What does privacy by design mean architecturally rather than as a policy statement, and which decisions must be made first?
2 min answer jupiterprivacyminimisationdefaults -
Privacy by Design advanced
What does privacy by design mean concretely at the point of designing a system, rather than as a principle?
1 min answer privacyminimisationdesigndefaults -
Privacy-Enhancing Technologies advanced
A product lead at a super-app of Tencent/WeChat's shape says the new on-device keyboard model can ship without a consent flow because federated learning means the data never leaves the phone. You have ten minutes at the architecture review board. What do you say and what would you actually build?
3 min answer federated-learningsecure-aggregationdifferential-privacyon-device-ml -
Privacy-Enhancing Technologies advanced
A statistics team wants to publish counts from a sensitive dataset under differential privacy. Working from the way the US Census Bureau ran its 2020 disclosure avoidance system, estimate how the privacy budget constrains what can be published and which choice dominates the accuracy you end up with.
3 min answer differential-privacycensusepsilonbudget -
Privacy-Enhancing Technologies advanced Multiple choice
Two retailers want the size of their shared customer overlap and the average basket of that overlap group without either seeing the other's customer list. Which technique fits the requirement as stated?
2 min answer psidifferential-privacyclean-roomhomomorphic-encryption -
Privacy-Enhancing Technologies advanced
What do privacy-enhancing technologies actually enable, and what do they cost in practice?
2 min answer privacy-techdifferential-privacyfederated-learninghomomorphic -
Pseudonymisation advanced
A travel metasearch of Expedia's shape replaces every traveller email with a deterministic HMAC token before the data reaches the analytics warehouse and before any file goes to an advertising partner. Two years later an audit finds that one partner can name individual travellers. The token vault was never breached. What failed?
3 min answer pseudonymisationtokenisationlinkabilityre-identification -
Pseudonymisation advanced
On 4 August 2006 AOL published about 20 million search queries from more than 650,000 users over three months, with usernames replaced by random numbers. Within days the New York Times had identified user 4417749 as a named individual from the content of her searches alone. What failed, which design assumption made it possible, and what would have prevented it?
3 min answer aolre-identificationquasi-identifiersanonymisation -
Pseudonymisation advanced
Pseudonymisation reduces regulatory obligations. What does it actually provide, and where is it commonly overstated?
2 min answer pseudonymisationanonymisationre-identificationkey-separation -
Records Retention & Legal Hold advanced
A regulated fintech must prove every customer-facing balance can be reconstructed from an audit trail. Compare event sourcing, CDC into an immutable log, and conventional tables with a triggered audit log.
3 min answer nubankevent-sourcingcdcaudit -
Records Retention & Legal Hold advanced
Litigation requires preserving all records relating to a matter, overriding normal retention. How is that implemented?
2 min answer legal-holdretentionpreservationdiscovery