Quiz
2667 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2667
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture95
Cost Architecture & FinOps92
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization92
AI-Era Architecture86
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture88
Streaming & Real-Time Data93
Data Governance & Semantics81
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk88
95 questions in Security Architecture.
-
Tokens & JWTs advanced
A team is designing token-based authentication for a distributed system. What are the significant design decisions, and which common JWT choices cause problems later?
2 min answer jwttokensrevocationsessions -
Tokens & JWTs advanced
After a routine signing key rotation, roughly 3% of API requests start failing with 401s. The rate decays over about ten minutes and returns on the next rotation. Tokens look valid and clocks are synchronised. What is happening?
3 min answer jwtjwkskey rotationcaching -
Tokens & JWTs advanced
An identity provider issues tokens that applications validate locally without a network call. What does that buy, and what is the necessary consequence for revocation?
2 min answer clerkauth0jwtrevocation -
Tokens & JWTs advanced
Your JWT-based auth means a fired employee keeps access for 15 minutes after their account is disabled. Security says that is unacceptable. What are the options?
2 min answer jwtrevocationtokenstradeoffs -
Tokens & JWTs intermediate
Your JWTs last one hour. An employee is dismissed. Security asks why they still had system access for 45 minutes. Explain and fix.
2 min answer jwtrevocationsessions -
Zero Trust advanced
A board mandate says "implement zero trust in twelve months". What do you actually do, in what order?
2 min answer zero-trustsequencingpragmatism -
Zero Trust advanced
A digital bank adopts zero trust. What actually changes in the architecture, and what is commonly mistaken for zero trust?
2 min answer jupiterzero-trustidentitymtls -
Zero Trust advanced
A platform replaces network-level trust with per-request authorisation - every call to every internal service is checked against a central policy service. Security is satisfied. What has the platform given up, and when does that bill arrive?
3 min answer zero trustauthorizationavailabilitylatency -
Zero Trust advanced
An organisation decides to adopt zero trust. What does it actually mean architecturally, what is the realistic implementation order, and where does it fail?
3 min answer zero-trustidentitymtlsnetwork-security -
Zero Trust advanced
An organisation replaces its VPN with an identity-aware access model. What actually has to change beyond the network, and where do these programmes stall?
2 min answer zero-trustidentitydevice-trustmigration -
Zero Trust advanced
How would you assess your estate's exposure to lateral movement, in a way that produces actionable findings?
2 min answer securityblast-radiusassessment