Quiz
2627 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2627
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture77
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture85
Cost Architecture & FinOps82
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization82
AI-Era Architecture86
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture88
Streaming & Real-Time Data93
Data Governance & Semantics81
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk88
85 questions in Security Architecture.
-
Authorization advanced
An internal API accepts a customer ID and returns that customer's data. It authenticates the calling service with mTLS. What is the flaw?
2 min answer authorizationconfused-deputyzero-trust -
Compliance Frameworks intermediate
A global employment platform passes its compliance audits and is repeatedly found to have real security weaknesses. What is the gap?
2 min answer deelcompliancecontrolsevidence -
Compliance Frameworks intermediate
A vendor platform must satisfy security certification requirements while serving customers across many jurisdictions. How should compliance influence architecture without paralysing it?
2 min answer compliancecontrolsautomationevidence -
Compliance Frameworks advanced
How would you reduce PCI DSS scope for an e-commerce platform, and what does it cost you?
2 min answer pcicompliancescope-reductiontokenisation -
Compliance Frameworks advanced
PCI DSS assessment covers 40 systems and costs a fortune annually. How would you reduce that architecturally?
2 min answer pciscopetokenisationcompliance -
Data Classification intermediate
A consumer finance platform wants to apply controls proportionate to data sensitivity. How should classification work so it actually drives behaviour?
2 min answer sliceclassificationcontrolsautomation -
Data Classification intermediate Multiple choice
A data platform labels tables as public internal confidential or restricted in its catalogue. Six months on an auditor finds restricted columns in a dashboard that 400 people can open. Which control would have actually prevented it?
3 min answer data classificationaccess controlgovernancemasking -
Data Classification intermediate
A developer needs to reproduce a bug that only occurs with a specific customer's data. What do you allow?
2 min answer privacyaccessoperations -
Data Classification intermediate
A platform handles customer addresses, payment details, order history, retailer pricing and shopper location. Why does data classification matter architecturally, and what goes wrong without it?
2 min answer data-classificationcontrolsresidencyretention -
Encryption advanced
A file storage platform encrypts data at rest and in transit. A customer asks whether the provider can read their files. What does the honest answer depend on, and what would change it?
2 min answer encryptionkey-managementend-to-endthreat-model -
Encryption intermediate Multiple choice
A regulator asks whether customer data is encrypted. The team says yes, disks are encrypted. Is that a sufficient answer?
2 min answer encryptionthreat-modelcompliance -
Encryption beginner Multiple choice
An attacker obtains the application's database credential from a leaked environment file and runs a SELECT against the customer table. Every volume is encrypted at rest with a managed key service and every connection uses TLS. What does that encryption prevent here?
3 min answer encryptionat restthreat modelaccess control