Quiz
2667 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2667
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture86
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture88
Streaming & Real-Time Data93
Data Governance & Semantics81
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk88
95 questions in Security Architecture.
-
OAuth 2.0 & OIDC advanced
A single-page app has used the OAuth implicit flow since 2017 and keeps the access token in localStorage. Security wants authorization code with PKCE behind a backend-for-frontend holding a cookie session. 180000 daily users and 40 third-party embeds must not be logged out. Sequence the migration.
3 min answer oauthpkcebackend-for-frontendmigration -
OAuth 2.0 & OIDC intermediate
A team proposes the OAuth password grant for your first-party mobile app because "it is our own app". Respond.
2 min answer oauthmobileauthentication -
OWASP Risks intermediate
A marketplace hosts seller-generated content including descriptions, images and shop pages. Which common web risks are amplified, and what controls apply?
2 min answer owaspxssuser-contentcsp -
OWASP Risks intermediate Multiple choice
A penetration test reports that every object identifier in your API is a sequential integer and flags insecure direct object reference. Ownership is checked in shared middleware on every route. Three endpoints still returned another user's data: a bulk update that takes an array of identifiers, a nested comment fetch, and a CSV export. Where do you look first?
3 min answer broken-access-controlidorobject-level-authorizationmiddleware -
OWASP Risks advanced
Broken access control is consistently the top application security risk. Which architectural decisions make it structurally less likely rather than relying on review?
2 min answer access-controlowaspstructureauthorisation -
Privacy Engineering advanced
A consumer platform with 40 million accounts receives about 600 subject access requests a month. Honouring one means assembling a person's data from 23 services that each own their own store. Estimate what the manual path costs and say what changes the number by an order of magnitude.
3 min answer dsargdprsubject-indexdata-lineage -
Privacy Engineering advanced
A discovery platform builds personalisation from user behaviour. What privacy-engineering decisions must be made early, and which are expensive to retrofit?
2 min answer privacydata-minimisationpurpose-limitationdeletion -
Privacy Engineering advanced
Design the mechanism by which a deletion request propagates through a system with a warehouse, a search index, backups and three third-party processors.
2 min answer privacydeletiongdprpropagation -
Privacy Engineering advanced
Product wants to add "customers who bought this also bought" using purchase history. What does privacy by design require here?
2 min answer privacypurpose-limitationminimisationgdpr -
Secrets Management advanced
A CI/CD platform runs untrusted code from external contributors and also holds deployment credentials. How should secrets be architected so a malicious pull request cannot exfiltrate them?
2 min answer secretsci-cduntrusted-codescoping -
Secrets Management intermediate
A payments platform's secrets are in environment variables, set once at deployment. What is wrong, and what should replace it?
2 min answer razorpaysecretsrotationworkload-identity -
Secrets Management intermediate
A team stores credentials in a secrets manager and considers the problem solved. What is still wrong, and what does a genuinely good secrets posture look like?
2 min answer secretsrotationworkload-identitycredentials