Quiz
2627 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2627
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture77
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture85
Cost Architecture & FinOps82
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization82
AI-Era Architecture86
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture88
Streaming & Real-Time Data93
Data Governance & Semantics81
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk88
21 questions in Security Architecture.
-
OWASP Risks intermediate
A marketplace hosts seller-generated content including descriptions, images and shop pages. Which common web risks are amplified, and what controls apply?
2 min answer owaspxssuser-contentcsp -
Secrets Management intermediate
A payments platform's secrets are in environment variables, set once at deployment. What is wrong, and what should replace it?
2 min answer razorpaysecretsrotationworkload-identity -
Secrets Management intermediate
A team stores credentials in a secrets manager and considers the problem solved. What is still wrong, and what does a genuinely good secrets posture look like?
2 min answer secretsrotationworkload-identitycredentials -
Secure API Design intermediate
A developer platform's API is used by thousands of external integrators. What security properties must be defaults rather than options?
2 min answer postmanapi-securitydefaultsscopes -
Threat Modelling intermediate
A commerce platform threat-models its checkout flow. Which threats are usually missed, and what makes a threat model useful rather than ceremonial?
2 min answer threat-modellingcheckoutabusestride -
Threat Modelling intermediate
A design review shows a threat model with one trust boundary — internet to application. What boundaries are missing?
2 min answer threat-modellingboundariesreview -
Threat Modelling intermediate
An insurance platform runs a threat modelling exercise that produces a long list nobody acts on. What went wrong, and what makes threat modelling useful?
2 min answer ackothreat-modellingprioritisationdesign -
Threat Modelling intermediate
Threat modelling is widely recommended and rarely practised sustainably. What makes it fail, and what does a version that survives contact with delivery look like?
2 min answer threat-modellingstridesecurity-reviewprocess -
Tokens & JWTs intermediate
Your JWTs last one hour. An employee is dismissed. Security asks why they still had system access for 45 minutes. Explain and fix.
2 min answer jwtrevocationsessions