Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security Questions

Embedding security into how software is built, assembled from dependencies, and shipped. Covers shift-left and secure-SDLC practices, infrastructure-as-code security, CI/CD pipeline and secrets management, integrating security scanning into build and deploy, and configuration and secret management across environments, together with software supply chain security: software composition analysis (SCA), dependency and open-source vulnerability management, build-provenance and artifact integrity, and mitigating supply-chain attack vectors. The 'secure the delivery pipeline and everything it pulls in' discipline, distinct from vendor-risk governance.

MediumSystem Design
91 practiced

Provide a sample CI/CD workflow (YAML or pseudocode) that enforces separation of duties: developers can build and push artifacts but cannot promote to production; release and deployment require an independent approver and only signed artifacts are promoted. Include artifact signing and verification and least-privilege runner identities.

HardTechnical
87 practiced

Design an algorithm or pseudocode for scanning build artifacts for likely secrets using a combination of entropy analysis and regex patterns. Describe how you would minimize false positives (for example by whitelisting) and automatically trigger a revocation workflow for confirmed leaks while avoiding noisy rotations.

MediumSystem Design
100 practiced

Design a CI/CD pipeline for a microservices web application showing where and when to run SAST, SCA, DAST, unit tests, and integration tests. Define security gates (which findings block progression), fail criteria, and a rollback strategy for DAST findings that are discovered post-merge. Discuss latency considerations and how to keep developer feedback fast.

HardTechnical
69 practiced

Assess the pros and cons of automatically blocking PR merges for vulnerabilities above a CVSS threshold vs allowing merges and auto-creating prioritized remediation tickets. Consider developer productivity, attack window, context-aware exploitability, and false positives. Recommend a policy that balances security and velocity and describe an exception process.

HardTechnical
96 practiced

Your organization detects unauthorized use of an HSM root key. Describe the forensic investigation steps, how to assess the scope and impact of the compromise on CI/CD pipelines and signing processes, and define a recovery and key-rotation strategy that preserves trust where possible.

Unlock Full Question Bank

Get access to all Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.