Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security Questions

Embedding security into how software is built, assembled from dependencies, and shipped. Covers shift-left and secure-SDLC practices, infrastructure-as-code security, CI/CD pipeline and secrets management, integrating security scanning into build and deploy, and configuration and secret management across environments, together with software supply chain security: software composition analysis (SCA), dependency and open-source vulnerability management, build-provenance and artifact integrity, and mitigating supply-chain attack vectors. The 'secure the delivery pipeline and everything it pulls in' discipline, distinct from vendor-risk governance.

MediumTechnical
98 practiced

Write an OPA (Rego) policy snippet that enforces two Kubernetes admission rules: 1) container images must come from registries 'mycompany.registry/' or 'gcr.io/mycompany/', and 2) containers must not be allowed to run as root (either securityContext.runAsNonRoot == true or securityContext.runAsUser != 0). Include brief comments explaining your logic. (Assume input is the Kubernetes admission review JSON.)

EasyTechnical
88 practiced

Define 'security gate' in a CI/CD context and explain the trade-offs between 'hard' gates (blocking merges/deploys) and 'soft' gates (warnings, automated tickets). When would you adopt each approach as a Security Architect, and how would you measure the impact on security posture and developer velocity?

EasyTechnical
86 practiced

Explain what a Software Bill of Materials (SBOM) is and why it matters as a security control (not just an inventory), and how artifact signing (for example cosign/Sigstore) improves supply-chain trust. Sketch a short example workflow: build -> generate SBOM -> sign artifact -> publish to registry -> verify at deploy time. Where do SLSA levels and keyless (OIDC-backed) signing fit into this picture?

EasyTechnical
85 practiced

Compare SAST, DAST, and SCA: for each type describe what artifacts it analyzes, at what stage(s) of the SDLC it is most effective, typical false-positive and false-negative trade-offs, and one practical example tool you would run in a CI pipeline. Also explain where each should be run (pre-merge, post-merge, nightly, or runtime) to optimize developer velocity and security coverage.

EasyTechnical
75 practiced

Explain 'policy-as-code' in the CI/CD context. Provide a simple example rule (textual) that would prevent merges if a commit contains high-severity SCA findings or secrets, and name two tools that can enforce such rules in pipelines.

Unlock Full Question Bank

Get access to all 24 Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.