01Security groups versus network ACLs: explain stateful and stateless, and give me a case where the difference bites.▼easy★ EssentialNewAmazonMicrosoftAccenture2 repliesunlockedAsked in almost every cloud screen, and most candidates recite the table without ever naming the failure it causes. The ephemeral port range is the whole answer.Open full answer →
03Walk me through how an AWS IAM request is evaluated. Where does an explicit deny fit?▼hard★ EssentialNewAmazonJPMorgan ChaseGoldman Sachs2 repliesunlockedThe question that separates console users from people who have debugged a permissions failure across accounts. Evaluation order is deterministic and knowing it makes AccessDenied readable.Open full answer →
04You need to connect forty VPCs plus on-premises. Peering, Transit Gateway or PrivateLink?▼hardNewAmazonJPMorgan ChaseWalmart Global Tech2 repliesunlockedA design question with a clear answer at this scale, and the reasoning is what scores. The three options solve different problems and peering and Transit Gateway connect networks while PrivateLink exposes services.Open full answer →
06An instance in a private subnet cannot reach the internet. Debug it in order.▼easy★ EssentialNewAmazonTCSInfosys2 repliesunlockedTrace the route and return path before changing rules. First establish whether the failing connection uses IPv4, IPv6 or a private service endpoint.Open full answer →
07You inherit 300 cloud accounts and thousands of roles. How do you get to least privilege without breaking production?▼hard★ EssentialNewAmazon & AWSJPMorgan ChaseGoldman SachsunlockedEveryone endorses least privilege; few can describe how they would measure over-permission across a fleet. The scoring answer names the evidence source, the tiered remediation, and the break-glass hatch that makes it survivable.Open full answer →