Quiz
2741 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2741
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience99
Observability92
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture96
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture102
Data Platform Architecture98
Streaming & Real-Time Data93
Data Governance & Semantics91
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk98
90 questions in Regulatory & Data Protection Architecture.
-
Financial Services Regulation advanced
An exit plan requirement must be credible and tested. What does that mean for how you build?
2 min answer exit-planportabilitylock-inregulation -
Financial Services Regulation advanced
What does financial services regulation demand of architecture that a general-purpose system does not provide?
1 min answer financial-servicesauditresiliencereporting -
Geo-Restriction & Sanctions advanced
A platform must block access from sanctioned jurisdictions and restrict content by market. How is this implemented and where does it fail?
1 min answer sanctionsgeo-blockingscreeningevasion -
Geo-Restriction & Sanctions intermediate Multiple choice
A trading platform must prevent sanctioned parties and prohibited jurisdictions from using the service. Geo-IP blocking is in place at the edge, and compliance reports that sanctioned individuals are still being onboarded. Where should the primary enforcement point be?
3 min answer sanctionsscreeninggeo-blockingkyc -
Geo-Restriction & Sanctions advanced
A trading platform must restrict access by jurisdiction and screen against sanctions lists. What must the architecture handle?
2 min answer coindcxsanctionsgeoscreening -
Geo-Restriction & Sanctions advanced
Sanctions lists change weekly. What does your architecture need so that is not a compliance risk?
2 min answer sanctionsscreeningrescreeningevidence -
Healthcare Data Protection advanced
A clinical system holds patient records used for care, research and operational analytics. How should access be architected?
1 min answer healthcareaccess-controlde-identificationaudit -
Healthcare Data Protection intermediate Multiple choice
An emergency department needs any clinician to reach any patient's record within seconds, while the privacy office requires minimum-necessary access. Which control set satisfies both?
2 min answer healthcarebreak-glassrbacaudit -
Healthcare Data Protection intermediate Multiple choice
At 02:40 the access-audit service behind an electronic health record starts taking 8 s per write instead of 12 ms. It returns no errors. Audit controls at 45 CFR 164.312(b) are a required implementation specification under the HIPAA Security Rule. What should the record system do while the audit path is degraded?
3 min answer hipaaaudit-loggingfail-opengraceful-degradation -
Healthcare Data Protection advanced
Why does health data access emphasise auditing over prevention, and what does that require architecturally?
2 min answer healthcarebreak-glassauditconsent -
Lawful Basis & Purpose Limitation beginner Multiple choice
A European travel marketplace of Booking.com's shape holds the same guest email twice: once captured at checkout so the booking confirmation can be sent, once captured at newsletter sign-up. The data team wants a single golden customer record and cannot see the objection. Which data model keeps the merge lawful?
3 min answer purpose-limitationgolden-recordmdmconsent -
Lawful Basis & Purpose Limitation advanced
A recommendation model was trained on browsing histories collected under consent. Several thousand users withdraw that consent. What happens to the model that has already learned from their data, and what makes your answer defensible?
3 min answer consent-withdrawaltraining-dataprovenanceretraining