Quiz
2627 questions of the kind that actually get asked — in interviews, in architecture review boards, and by the person who has to run the thing at 3 AM. Every answer states the trade-off rather than the slogan, and says when the obvious choice is the wrong one.
All areas2627
Architecture Fundamentals81
Distributed Systems101
Data Architecture90
Cloud Architecture77
Networking86
API & Integration Architecture78
Reliability & Resilience88
Observability81
Performance & Capacity Engineering90
Security Architecture85
Cost Architecture & FinOps82
Business Architecture93
Architecture Communication91
Enterprise Architecture91
Legacy Modernization82
AI-Era Architecture86
Software Architecture & Engineering84
Architecture Patterns84
Architecture Decision-Making91
The Architect's Meta-Skills92
Delivery & Release Engineering93
Platform Engineering & Developer Experience92
Testing & Quality Architecture90
Data Platform Architecture88
Streaming & Real-Time Data93
Data Governance & Semantics81
Frontend & Experience Architecture91
Edge, Mobile & IoT88
Regulatory & Data Protection Architecture90
Assurance, Audit & Model Risk88
85 questions in Security Architecture.
-
Auditability advanced
A regulated brokerage must prove after the fact who did what, to which account, and on whose authority. What must the architecture provide?
2 min answer growwauditimmutabilityevidence -
Auditability advanced
A travel platform must be able to answer, months later, who changed a booking and what they saw. What does that require architecturally, and why is a log table insufficient?
2 min answer auditabilityaudit-logattributionimmutability -
Auditability advanced
Design the audit logging for a system handling financial transactions. What is logged, where does it go, and what makes it hold up?
2 min answer auditintegrityretentioncompliance -
Auditability advanced
Your audit logs are stored in a platform administered by the same team that has production access. What is the problem?
2 min answer auditinsider-riskcontrols -
Authentication advanced
A multi-product company must unify authentication across products that each built their own login. What is the migration risk, and how is it sequenced?
2 min answer authenticationidentitymigrationsso -
Authentication advanced Multiple choice
For service-to-service authentication inside a cluster, would you use mTLS, OAuth client credentials, or both?
2 min answer mtlsoauthservice-identity -
Authentication advanced
In 2022 the same SMS phishing campaign hit Twilio and Cloudflare within days of each other. Twilio reported unauthorised access to data belonging to around 209 of its roughly 270000 customer accounts. Cloudflare reported that three employees entered credentials on the fake page and that no systems were compromised. What structural difference produced two different outcomes?
3 min answer twiliocloudflarephishingfido2 -
Authentication advanced
You must roll out MFA to 40,000 employees. Security wants hardware keys; the service desk fears the call volume. Design the rollout.
2 min answer mfaphishing-resistantrolloutrisk -
Authorization advanced
A collaboration platform adds shared channels between separate customer organisations. What data-boundary problems does this create, and how should authorization be modelled?
3 min answer slackmulti-tenancycross-orgauthorization -
Authorization advanced
A document collaboration product needs sharing with individuals, teams, and inherited folder permissions. Which authorization model?
2 min answer authorizationrebacrbacmodelling -
Authorization advanced
A multi-tenant platform must guarantee that one customer can never see another's data. Where should that check live, and what makes the guarantee credible?
2 min answer workosmulti-tenancyisolationauthorization -
Authorization advanced
A workspace product has pages nested arbitrarily deep, with permissions inheritable and overridable at any level, shared with individuals, groups and guests. How should authorization be designed so checks stay fast and correct?
2 min answer authorizationpermissionsinheritancecaching