Quiz
2908 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2908
Architecture Fundamentals91
Distributed Systems101
Data Architecture90
Cloud Architecture87
Networking86
API & Integration Architecture87
Reliability & Resilience99
Observability92
Performance & Capacity Engineering100
Security Architecture95
Cost Architecture & FinOps102
Business Architecture103
Architecture Communication102
Enterprise Architecture100
Legacy Modernization92
AI-Era Architecture96
Software Architecture & Engineering93
Architecture Patterns94
Architecture Decision-Making101
The Architect's Meta-Skills102
Delivery & Release Engineering103
Platform Engineering & Developer Experience102
Testing & Quality Architecture102
Data Platform Architecture98
Streaming & Real-Time Data103
Data Governance & Semantics91
Frontend & Experience Architecture101
Edge, Mobile & IoT98
Regulatory & Data Protection Architecture99
Assurance, Audit & Model Risk98
4 questions in OAuth 2.0 & OIDC.
-
OAuth 2.0 & OIDC advanced
A developer platform issues OAuth tokens to third-party applications. What scope design decisions determine whether the platform can be operated safely long term?
2 min answer oauthscopesleast-privilegethird-party -
OAuth 2.0 & OIDC beginner Multiple choice
A mobile client sends its OAuth access token as `?access_token=...` because an intermediate proxy strips the Authorization header. Six weeks later the live token values appear in a CDN edge log that 60 engineers can query and in a partner's referrer report. Which change actually closes this?
3 min answer oauthbearer-tokenloggingtoken-leakage -
OAuth 2.0 & OIDC advanced
A single-page app has used the OAuth implicit flow since 2017 and keeps the access token in localStorage. Security wants authorization code with PKCE behind a backend-for-frontend holding a cookie session. 180000 daily users and 40 third-party embeds must not be logged out. Sequence the migration.
3 min answer oauthpkcebackend-for-frontendmigration -
OAuth 2.0 & OIDC intermediate
A team proposes the OAuth password grant for your first-party mobile app because "it is our own app". Respond.
2 min answer oauthmobileauthentication