Skip to content
Tech Interview Prep home
Technical interview guide

IAM & Security Fundamentals

The principle of least privilege, and how roles/policies enforce it instead of relying on long-lived credentials.

Read
24 min
Practice MCQs
25
Interview QA
25
Edition
v4
Editorial status
Reviewed

Scope: Vendor-neutral IAM fundamentals with AWS IAM, STS, Access Analyzer, CloudTrail, and KMS references accessed 2026-08-30..

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Explain authentication and authorization using a request to delete one production resource.

QA-2

Design human access to 30 cloud accounts for employees, contractors, and administrators.

QA-3

How should a production workload obtain cloud credentials without storing access keys?

QA-4

Compare temporary credentials with long-lived access keys, including remaining risks.

QA-5

Describe a practical process for reaching and maintaining least privilege for an existing application.

QA-6

Walk through an IAM policy statement and explain how action, resource, effect, and condition interact.

QA-7

Explain implicit deny and explicit deny, and give a safe use for each.

QA-8

Compare identity policies, resource policies, permissions boundaries, session policies, and organization guardrails.

QA-9

How would you use a permissions boundary to delegate IAM role creation to a development team?

QA-10

What should an organization-level service control policy do, and what should it avoid?

QA-11

Review a role design by separating its trust policy from its permissions policies.

QA-12

Design least-privilege cross-account access for a central security team.

QA-13

Explain the confused-deputy problem for a multi-tenant SaaS provider that assumes customer roles.

QA-14

Design MFA enrollment, enforcement, and recovery for privileged administrators.

QA-15

Define a secure root-account and break-glass operating model.

QA-16

Design the lifecycle for a database password used by multiple application instances.

QA-17

Compare RBAC and ABAC for a platform with hundreds of teams and projects.

QA-18

How would you review a deployment role for privilege-escalation paths?

QA-19

How do you detect, safely remove, and continuously enforce least privilege against unused IAM permissions at scale without breaking production services?

QA-20

What IAM and STS audit events should be centralized, and how would you detect abuse?

QA-21

Design a break-glass process that remains usable but cannot become a quiet bypass.

QA-22

Explain envelope encryption and the authorization boundaries around decrypting application data.

QA-23

Respond to a leaked production access key discovered in a public repository.

QA-24

Design OIDC federation from a CI/CD platform into a production deployment role.

QA-25

Troubleshoot an access-denied response when the role's attached policy appears to allow the action.