Quiz
2667 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2667
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture86
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture88
Streaming & Real-Time Data93
Data Governance & Semantics81
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk88
95 questions in Security Architecture.
-
Security Incident Response advanced
You discover an attacker holds valid credentials in your environment. What are your first three actions and what must already exist for them to be possible?
2 min answer incident-responsecontainmentforensicscredentials -
Key Management advanced
A communication platform adds end-to-end encryption to multi-party meetings. What are the hard problems, and which are cryptographic versus operational?
2 min answer key-managemente2eegroup-keystrust -
Key Management advanced
A crypto exchange must hold customer assets while remaining operationally usable. How should key custody, signing, approval and monitoring be architected?
2 min answer coindcxcustodyhsmsegregation -
Key Management advanced
A pipeline writes 200 million objects a day and the security review requires per-object encryption with a managed key service. Roughly how many calls to that service does the naive design make, what does it cost, and what changes the answer by two orders of magnitude?
3 min answer envelope encryptionkmsdata keysthroughput -
Key Management advanced
In a multi-tenant SaaS, would you use one data encryption key for all tenants or one per tenant? Justify.
2 min answer encryptiontenancyerasure -
Network Security beginner
A security questionnaire asks whether data is encrypted in transit and the team answers yes because the load balancer serves TLS 1.3. What happens if an attacker gets code execution on one host behind that load balancer, and what has the TLS answer actually bought?
2 min answer tlsterminationmtlslateral-movement -
Network Security advanced
All outbound traffic from a cluster passes through an egress proxy that enforces allowlists and TLS inspection. The proxy does not fail; it gets slow, with p99 rising from 20 ms to 6 s. What happens across the platform over the next ten minutes?
3 min answer egressproxythread exhaustiontimeouts -
Network Security intermediate
An enterprise wants to segment its network so that a compromised application server cannot reach the database directly. What does segmentation actually buy, and what commonly undermines it?
2 min answer network-securitysegmentationlateral-movementdefence-in-depth -
Network Security intermediate
Review this design. 12 services and 8 engineers in one cloud region. The proposal adds a service mesh with mutual TLS between every pair of services plus per-service microsegmentation policy plus an external policy decision point consulted on every internal call plus envelope encryption with one data key per record. What would you remove?
3 min answer over-engineeringservice-meshpolicy-decision-pointenvelope-encryption -
Network Security advanced
You propose egress filtering. Engineering says it will break builds and slow delivery. How do you proceed?
2 min answer network-securityexfiltrationadoption -
OAuth 2.0 & OIDC advanced
A developer platform issues OAuth tokens to third-party applications. What scope design decisions determine whether the platform can be operated safely long term?
2 min answer oauthscopesleast-privilegethird-party -
OAuth 2.0 & OIDC beginner Multiple choice
A mobile client sends its OAuth access token as `?access_token=...` because an intermediate proxy strips the Authorization header. Six weeks later the live token values appear in a CDN edge log that 60 engineers can query and in a partner's referrer report. Which change actually closes this?
3 min answer oauthbearer-tokenloggingtoken-leakage