Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security Questions
Embedding security into how software is built, assembled from dependencies, and shipped. Covers shift-left and secure-SDLC practices, infrastructure-as-code security, CI/CD pipeline and secrets management, integrating security scanning into build and deploy, and configuration and secret management across environments, together with software supply chain security: software composition analysis (SCA), dependency and open-source vulnerability management, build-provenance and artifact integrity, and mitigating supply-chain attack vectors. The 'secure the delivery pipeline and everything it pulls in' discipline, distinct from vendor-risk governance.
Assess the pros and cons of automatically blocking PR merges for vulnerabilities above a CVSS threshold vs allowing merges and auto-creating prioritized remediation tickets. Consider developer productivity, attack window, context-aware exploitability, and false positives. Recommend a policy that balances security and velocity and describe an exception process.
A pipeline runner was compromised and an attacker inserted a malicious build step that pushed a backdoored image to production. Describe detection methods to identify the compromise, containment steps across CI and production (including registry and K8s), evidence collection for forensics, remediation actions (revocation, rebuild, redeploy), and long-term controls to prevent recurrence.
Define 'security gate' in a CI/CD context and explain the trade-offs between 'hard' gates (blocking merges/deploys) and 'soft' gates (warnings, automated tickets). When would you adopt each approach as a Security Architect, and how would you measure the impact on security posture and developer velocity?
Describe supply chain attacks against software: how attackers compromise dependencies, CI/CD pipelines, or vendor updates. Provide two historical examples, indicators of compromise to hunt for, and three proactive controls you would implement across procurement and engineering to reduce risk.
Explain 'policy-as-code' in the CI/CD context. Provide a simple example rule (textual) that would prevent merges if a commit contains high-severity SCA findings or secrets, and name two tools that can enforce such rules in pipelines.
Unlock Full Question Bank
Get access to all 35 Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security interview questions and detailed answers.
Sign in to ContinueJoin thousands of developers preparing for their dream job.