Zero Trust, Segmentation, and Service-to-Service Security Questions

Designing network and service-communication trust models where no implicit trust is granted by network location. Covers zero-trust access, microsegmentation and identity-aware perimeters, least-privilege network access, lateral-movement prevention, and segmenting environments to contain blast radius, together with securing service-to-service communication in distributed and microservices architectures: mutual authentication between services, service mesh security, multi-tenancy isolation, east-west traffic, and the security implications of scale and geographic distribution. The architectural trust-boundary pattern and its enforcement across decomposed, high-scale systems, distinct from device-level firewall configuration.

MediumTechnical
41 practiced

Compare JSON Web Tokens and opaque tokens for service authentication: local verification versus introspection, how each is revoked, size and transport considerations, and when you'd prefer one over the other. What common mistakes should a reviewer look for when a service validates a JWT (algorithm confusion, missing audience or expiry checks)?

HardSystem Design
60 practiced

Design a fine-grained authorization model for a large number of microservices: evaluate RBAC, ABAC, and a hybrid approach, and decide where policy evaluation should happen (central decision point, sidecar, or in-process library). Give a concrete example of one authorization rule your design would enforce.

MediumTechnical
35 practiced

Write a policy-as-code snippet (Open Policy Agent / Rego, or an equivalent policy language of your choice) that authorizes a service-to-service request only when: the caller's JWT audience claim matches the target service, the caller's role is on that service's access list, and the caller's device posture score meets a minimum bar. Explain what each clause is protecting against.

MediumTechnical
41 practiced

Compare the main approaches for authenticating one service to another: mutual TLS via a service mesh with workload identities (e.g. SPIFFE/SPIRE), signed JWTs issued by a central authority, and cloud-native IAM roles or client certificates. What's the trust model, key-rotation story, and operational overhead for each, and how would you decide between them for a multi-team, multi-namespace environment?

MediumTechnical
46 practiced

How does continuous authentication and authorization differ from a one-time login? What signals (behavioral, location, device posture) should trigger re-authentication or an adaptive change in access, and how do you avoid re-prompting the user so often that they get fatigued?

Unlock Full Question Bank

Get access to all 15 Zero Trust, Segmentation, and Service-to-Service Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.