Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security Questions

Embedding security into how software is built, assembled from dependencies, and shipped. Covers shift-left and secure-SDLC practices, infrastructure-as-code security, CI/CD pipeline and secrets management, integrating security scanning into build and deploy, and configuration and secret management across environments, together with software supply chain security: software composition analysis (SCA), dependency and open-source vulnerability management, build-provenance and artifact integrity, and mitigating supply-chain attack vectors. The 'secure the delivery pipeline and everything it pulls in' discipline, distinct from vendor-risk governance.

HardTechnical
69 practiced

Assess the pros and cons of automatically blocking PR merges for vulnerabilities above a CVSS threshold vs allowing merges and auto-creating prioritized remediation tickets. Consider developer productivity, attack window, context-aware exploitability, and false positives. Recommend a policy that balances security and velocity and describe an exception process.

HardTechnical
90 practiced

A pipeline runner was compromised and an attacker inserted a malicious build step that pushed a backdoored image to production. Describe detection methods to identify the compromise, containment steps across CI and production (including registry and K8s), evidence collection for forensics, remediation actions (revocation, rebuild, redeploy), and long-term controls to prevent recurrence.

EasyTechnical
88 practiced

Define 'security gate' in a CI/CD context and explain the trade-offs between 'hard' gates (blocking merges/deploys) and 'soft' gates (warnings, automated tickets). When would you adopt each approach as a Security Architect, and how would you measure the impact on security posture and developer velocity?

EasyTechnical
100 practiced

Describe supply chain attacks against software: how attackers compromise dependencies, CI/CD pipelines, or vendor updates. Provide two historical examples, indicators of compromise to hunt for, and three proactive controls you would implement across procurement and engineering to reduce risk.

EasyTechnical
75 practiced

Explain 'policy-as-code' in the CI/CD context. Provide a simple example rule (textual) that would prevent merges if a commit contains high-severity SCA findings or secrets, and name two tools that can enforce such rules in pipelines.

Unlock Full Question Bank

Get access to all 35 Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.