Quiz
2741 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2741
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience99
Observability92
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture96
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture102
Data Platform Architecture98
Streaming & Real-Time Data93
Data Governance & Semantics91
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk98
90 questions in Regulatory & Data Protection Architecture.
-
Records Retention & Legal Hold advanced
On 27 September 2022 the SEC and CFTC announced settlements with 15 broker-dealers and one investment adviser totalling over $1.1bn, with individual SEC penalties ranging from $10M to $125M, for failing to preserve business communications conducted on personal messaging apps. What was the architectural failure, and what does it teach about capture obligations generally?
3 min answer secrecordkeepingcaptureretention -
Records Retention & Legal Hold advanced
Your automated retention job deletes records after seven years. Legal informs you that litigation is anticipated involving accounts from nine years ago. What now?
2 min answer legal-holdretentionarchitecture -
Regulatory & Data Protection Architecture advanced Multiple choice
A global enterprise application must satisfy different regulatory regimes per market. Where should regulatory logic live?
1 min answer regulatoryconfigurationpolicy-as-codemulti-jurisdiction -
Regulatory & Data Protection Architecture advanced
How do you make a data residency requirement a structural property rather than a policy?
2 min answer residencycellscontrol-planeenforcement -
Regulatory & Data Protection Architecture beginner
Marketing has signed with an analytics vendor and the vendor's SDK is due in next week's mobile release. Legal asks whether you are the controller or the processor for what that SDK collects. Why does the answer change the architecture rather than only the paperwork?
2 min answer controllerprocessorsub-processorssdk -
Regulatory Reporting Pipelines advanced
A regulatory return was submitted three months ago. A reference-data correction arrives showing that a counterparty classification was wrong for 14 months, which changes figures in that return and in the five before it. What happens next, and what must the pipeline have supported for this to be manageable?
3 min answer regulatory-reportingrestatementbitemporallineage -
Regulatory Reporting Pipelines advanced
A regulatory submission is found to be wrong. You must produce an amended figure and explain the difference. What must the pipeline have supported?
2 min answer reportinglineagereproducibility -
Regulatory Reporting Pipelines advanced
An insurer must submit regulatory reports whose format and content change periodically. How should the pipeline be designed?
2 min answer digitreportingmappingreproducibility -
Regulatory Reporting Pipelines advanced
Design a pipeline producing periodic regulatory submissions where every figure must be defensible years later.
1 min answer regulatory-reportingreproducibilitylineagecontrols -
Sector Cloud Rules advanced
A regulated institution must satisfy sector-specific rules on outsourcing to cloud providers. What does architecture need to demonstrate?
1 min answer outsourcingcloud-regulationexitoversight -
Sector Cloud Rules advanced
Sector rules require audit rights over providers and a tested exit plan. How does that shape your architecture and supplier choices?
2 min answer outsourcingaudit-rightsconcentrationexit -
Sector Cloud Rules advanced
The EU's Digital Operational Resilience Act has applied to financial entities since 17 January 2025. It requires a maintained register of every contractual arrangement with an ICT third-party provider, threat-led penetration testing, and brings designated critical providers under direct supervisory oversight. What does an architecture team gain from this, what does it pay, and when does the bill land?
3 min answer dorathird-party-riskregisterresilience-testing