Quiz
2707 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2707
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture96
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture98
Streaming & Real-Time Data93
Data Governance & Semantics91
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk98
11 questions in Regulatory & Data Protection Architecture.
-
Consent Architecture intermediate
A customer withdrew marketing consent three weeks ago and is still receiving emails. The consent record is correct. Where is the failure?
2 min answer consentintegrationcompliance -
Cross-Border Transfer intermediate Multiple choice
An EU-based SaaS product runs entirely in Frankfurt. Its 24-hour support rota includes engineers in a country without an adequacy decision, who can view customer records to diagnose issues. Legal flags this as a cross-border transfer. Which control best addresses the finding?
3 min answer cross-border-transfersupport-accessdata-minimisationscc -
Data Subject Rights intermediate
A regulator asks how long after an erasure request the data is genuinely gone. Production deletes in seconds; backups are daily with 35-day retention; the warehouse is fed by change data capture; the search index rebuilds weekly; three processors hold copies. Roughly what number do you give and what does it rule out?
2 min answer erasurebackupssuppression-listcdc -
Geo-Restriction & Sanctions intermediate Multiple choice
A trading platform must prevent sanctioned parties and prohibited jurisdictions from using the service. Geo-IP blocking is in place at the edge, and compliance reports that sanctioned individuals are still being onboarded. Where should the primary enforcement point be?
3 min answer sanctionsscreeninggeo-blockingkyc -
Healthcare Data Protection intermediate Multiple choice
An emergency department needs any clinician to reach any patient's record within seconds, while the privacy office requires minimum-necessary access. Which control set satisfies both?
2 min answer healthcarebreak-glassrbacaudit -
Healthcare Data Protection intermediate Multiple choice
At 02:40 the access-audit service behind an electronic health record starts taking 8 s per write instead of 12 ms. It returns no errors. Audit controls at 45 CFR 164.312(b) are a required implementation specification under the HIPAA Security Rule. What should the record system do while the audit path is degraded?
3 min answer hipaaaudit-loggingfail-opengraceful-degradation -
PCI-DSS Scoping intermediate
An e-commerce site collects card details in its own form and posts them to a payment provider's API. What would you change and why?
2 min answer stripepciscopesecurity -
Privacy by Design intermediate
Product wants to add a recommendation feature using browsing history. Legal asks for a data protection impact assessment. What does architecture need to supply?
2 min answer privacydpiadesigncompliance -
Pseudonymisation intermediate Multiple choice
A product analytics team needs per-user aggregation over two years of events without holding data that re-identifies people if the warehouse leaks. Which approach actually delivers that?
2 min answer pseudonymisationtokenisationhashingkey-custody -
Sector Cloud Rules intermediate
Until 2025 a European firm's cloud exit plan priced the egress bill as the main barrier and assumed the migration window was negotiable. The EU Data Act has applied since 12 September 2025 and removes switching charges entirely from 12 January 2027 while capping the switching timetable. What changed for the architecture team and what did not?
3 min answer eu-data-actcloud-exitfunctional-equivalenceconcentration-risk -
Third-Party Risk intermediate
Your KYC verification vendor is down for six hours. Customer onboarding stops. The board asks why a vendor outage became your outage.
2 min answer vendorsresiliencedegradation