Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security Questions
Embedding security into how software is built, assembled from dependencies, and shipped. Covers shift-left and secure-SDLC practices, infrastructure-as-code security, CI/CD pipeline and secrets management, integrating security scanning into build and deploy, and configuration and secret management across environments, together with software supply chain security: software composition analysis (SCA), dependency and open-source vulnerability management, build-provenance and artifact integrity, and mitigating supply-chain attack vectors. The 'secure the delivery pipeline and everything it pulls in' discipline, distinct from vendor-risk governance.
Explain 'policy-as-code' in the CI/CD context. Provide a simple example rule (textual) that would prevent merges if a commit contains high-severity SCA findings or secrets, and name two tools that can enforce such rules in pipelines.
In your own words, define DevSecOps and explain how it differs from a traditional SDLC where security is a separate, centralized gate. Describe the shift in people, process, and technology: who owns security tasks at each stage, which activities move to developers (pre-commit checks, local SAST), and which stay centralized (enterprise key management, threat intel). What benefits and common pitfalls do organizations hit when adopting it?
Write a GitHub Actions workflow YAML named 'dependency-scan.yml' that runs a software composition analysis (SCA) using Trivy (or Snyk) for a Node.js repository. The workflow must run on pull_request events, scan dependencies, upload a JSON or SARIF report as an artifact, and fail the job if any vulnerability of severity 'CRITICAL' is discovered. Keep the workflow minimal but functional.
You discover a third-party library used in production may have licensing or security exposure. Describe how you would investigate the risk, propose remediation options, communicate trade-offs to product and legal, and implement a plan to remediate while minimizing disruption to shipping schedules.
Describe the common ways secrets accidentally end up in Git history or CI artifacts. For each leakage vector, provide two concrete preventive controls you would implement (tooling, process, or policy) to stop that class of leak.
Unlock Full Question Bank
Get access to all 24 Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security interview questions and detailed answers.
Sign in to ContinueJoin thousands of developers preparing for their dream job.