DevSecOps Engineer Interview

preview_player
Показать описание
Join our Whatsapp Group for future Videos:

Join our Telegram Group for future Videos:
Рекомендации по теме
Комментарии
Автор

Join our Whatsapp/Telegram Groups for future Videos and Community Discussions:

Join our DevOps and Cloud Army to get access to members-only content and for direct 1-to-1 reach...

DevOps-Cloud
Автор

Questions in this interview :

What is the overarching objective of DevSecOps, and what exactly are we aiming to achieve with its implementation?
What is the DevSecOps pipeline?
What is DevOps?
What is the term for integrating security measures at the early stages of software development?
What is the DevSecOps recommendation for developers coding on their workstations?
How can you determine that a new plugin will not introduce issues and that old plugins have existing issues?
How can a developer ensure that a package downloaded from a public repository and referenced in their application is free from issues?
Why do you recommend using the latest version of a package, and how can its compatibility and security with the application be determined during testing?
How can you ensure the security and compatibility of a binary or package for which you do not have the source code?
What is the difference between static and dynamic security testing?
What are some software tools available for both static and dynamic security testing?
Which products are suitable for static security testing and which are suitable for dynamic security testing?
What kinds of issues are usually reported by static analysis security tools? What are the top two or three findings?
What are some examples of security issues commonly reported by static analysis tools like SonarQube?
Are you aware of cross-site scripting (XSS) and SQL injection vulnerabilities?
How can cluster-level security be maintained, particularly in terms of managing secrets properly?
What are the top two or three security issues you have observed when people create Docker containers?
What is the default user that a Docker container runs as, and what are the top two or three security issues you have observed when people create Docker containers?
What security issues have you observed when creating Docker containers, and what recommendations have you made to your development team to ensure container security?
What standards or practices do you follow to ensure that the containers created within Kubernetes are secure, especially when users are given specific permissions to view certain namespaces?
How would you configure your monitoring solution to detect if users are unable to access yahoo.com, and how would it alert you in such a scenario?
When the application check fails to access yahoo.com, how would you like your monitoring system to notify you?
Why wouldn't Prometheus, Grafana, or CloudWatch be useful in this scenario?
How would the monitoring system indicate a failure, such as by turning red?
How do you ensure that your containers are not exposed or at risk, especially if they are hacked and commands are run within them? Do Prometheus, Grafana, or CloudWatch have the capabilities to detect such security breaches?

KamranAli-lxcm
Автор

I understand that he is facing difficulties in responding and has communication challenges, but I appreciate his courage to attend the interview despite it being broadcast on YouTube and available to the public.

ragook
Автор

Can we have answers to the questions you've asked? It'll better help us in deep details please

zuiokopl
Автор

If only I can speak clearly in English…

He could have better diagrams at least.
One question I would like to ask you.
What you prefer?
Short ans or long?

cimihan
Автор

I appreciate that he attended the interview, but he seemed very confused, even with some basic concepts. I'm not sure why he chose to present that diagram during the interview; we should have just focused on QA. If technical writing was required, he could have shared his screen. Additionally, his introduction was not up to the mark.

KamranAli-lxcm
Автор

You mentioned you may consider him for a senior Devops role… is that actually true ? because to me he doesn’t seem at that level yet not sure if I’m being harsh

kway
Автор

Just heard bunch of key words put together . Did not make much sense

zekon-grkd