DevSecOps Interview Questions
Top DevSecOps interview questions and answers covering Secure SDLC, Shift Left Security, SAST, DAST, SCA, Container Security, Kubernetes Security, Supply Chain Security, SBOM, Zero Trust, SIEM, SOAR, and enterprise production scenarios.
Introduction
DevSecOps has become one of the most important skills for modern DevOps Engineers, Platform Engineers, Cloud Engineers, Security Engineers, SREs, and Solution Architects.
Interviewers expect candidates to understand not only security tools but also how security integrates throughout the software development lifecycle, CI/CD pipelines, Kubernetes platforms, cloud environments, and production systems.
This guide contains the most frequently asked enterprise DevSecOps interview questions.
Enterprise DevSecOps Architecture
flowchart LR
Developer --> GitHub --> CI
CI --> SAST
CI --> SCA
CI --> ContainerScan
CI --> IaCScan
CI --> ImageSigning
CI --> Registry
Registry --> ArgoCD
ArgoCD --> Kubernetes
Kubernetes --> Falco
Falco --> SIEM
SIEM --> SOC
DevSecOps Basics
1. What is DevSecOps?
Answer
DevSecOps integrates security into every phase of software development and operations.
Instead of performing security only before production deployment, security becomes part of
- Development
- Build
- Testing
- Deployment
- Runtime
- Monitoring
2. Why is DevSecOps important?
Benefits
- Early Vulnerability Detection
- Faster Releases
- Reduced Risk
- Automated Security
- Better Compliance
- Lower Cost
3. Difference between DevOps and DevSecOps?
| DevOps | DevSecOps |
|---|---|
| Automation | Secure Automation |
| Faster Delivery | Secure Delivery |
| Security Later | Security Everywhere |
| Shared Operations | Shared Security Responsibility |
Shift Left Security
4. What is Shift Left Security?
Security activities are performed earlier in the SDLC.
Examples
- Secure Coding
- SAST
- Dependency Scanning
- Secret Detection
Benefits
- Faster Fixes
- Lower Cost
- Better Security
Secure SDLC
5. What is Secure SDLC?
Secure SDLC integrates security into every software development phase.
flowchart LR
Planning --> Design --> Development --> Testing --> Deployment --> Monitoring
Security activities include
- Threat Modeling
- Secure Coding
- Security Testing
- Monitoring
Security Testing
6. What is SAST?
Static Application Security Testing analyzes source code without executing the application.
Finds
- SQL Injection
- XSS
- Hardcoded Secrets
- Insecure Coding Patterns
Popular Tools
- SonarQube
- Checkmarx
- Semgrep
- Fortify
7. What is DAST?
Dynamic Application Security Testing scans a running application.
Finds
- Authentication Issues
- Runtime Vulnerabilities
- API Security Problems
Popular Tools
- OWASP ZAP
- Burp Suite
8. Difference between SAST and DAST?
| SAST | DAST |
|---|---|
| Source Code | Running Application |
| Early SDLC | After Deployment |
| White Box | Black Box |
| Fast Feedback | Runtime Testing |
9. What is SCA?
Software Composition Analysis scans third-party libraries.
Detects
- Vulnerable Dependencies
- License Issues
- Outdated Packages
Popular Tools
- Snyk
- Dependabot
- Mend
- OWASP Dependency-Check
Secrets Management
10. Why should secrets never be stored in Git?
Because repositories may expose
- Passwords
- API Keys
- Tokens
- Certificates
Use
- HashiCorp Vault
- AWS Secrets Manager
- Azure Key Vault
Container Security
11. How do you secure Docker images?
Best Practices
- Minimal Base Images
- Scan Images
- Run as Non-root
- Remove Unused Packages
- Sign Images
12. Which tools scan container images?
Examples
- Trivy
- Grype
- Clair
Infrastructure Security
13. What is IaC Security?
Infrastructure as Code templates are scanned before deployment.
Checks
- Public Storage Buckets
- Open Security Groups
- Weak IAM Policies
- Encryption Disabled
Tools
- Checkov
- tfsec
- Terrascan
Kubernetes Security
14. How do you secure Kubernetes?
Security Areas
- RBAC
- Network Policies
- Secrets
- Admission Controllers
- Runtime Monitoring
15. What are Admission Controllers?
Admission Controllers validate requests before Kubernetes creates resources.
Examples
- Gatekeeper
- Kyverno
Policy as Code
16. What is Policy as Code?
Policies are written as code and automatically enforced.
Benefits
- Automation
- Compliance
- Governance
- Consistency
17. What is OPA?
Open Policy Agent validates security rules.
Example Policies
- No Privileged Containers
- Mandatory Labels
- Resource Limits
18. Difference between OPA and Kyverno?
| OPA | Kyverno |
|---|---|
| General Policy Engine | Kubernetes Native |
| Uses Rego | Uses YAML |
| Flexible | Easier Learning |
Supply Chain Security
19. What is Software Supply Chain Security?
Protects
- Source Code
- Dependencies
- Build Pipelines
- Container Images
- Registries
Goal
Only trusted software reaches production.
20. What is SBOM?
Software Bill of Materials.
Contains
- Dependencies
- Versions
- Licenses
- Components
Benefits
- Compliance
- Faster CVE Response
- Supply Chain Visibility
21. What is Image Signing?
Digitally signs container images.
Benefits
- Integrity
- Authenticity
- Tamper Detection
Popular Tool
- Cosign
Runtime Security
22. What is Runtime Security?
Protects applications after deployment.
Detects
- Container Escape
- Privilege Escalation
- Reverse Shells
- Suspicious Processes
23. What is Falco?
Falco monitors Linux kernel events.
Detects
- Shell Access
- File Modifications
- Privilege Escalation
- Container Escape
Zero Trust
24. What is Zero Trust?
Security model based on
"Never Trust, Always Verify"
Principles
- Identity Verification
- Least Privilege
- Continuous Authentication
Cloud Security
25. Which cloud security services have you used?
AWS
- IAM
- GuardDuty
- Security Hub
- Inspector
- KMS
Azure
- Defender for Cloud
Google Cloud
- Security Command Center
SIEM & SOAR
26. What is SIEM?
Security Information and Event Management.
Collects
- Logs
- Events
- Alerts
- Audit Data
Examples
- Splunk
- Microsoft Sentinel
- IBM QRadar
27. What is SOAR?
Security Orchestration, Automation and Response.
Automates
- Incident Response
- Alert Correlation
- Ticket Creation
- Threat Investigation
CI/CD Security
28. How do you secure a CI/CD pipeline?
Best Practices
- Code Reviews
- SAST
- SCA
- IaC Scanning
- Image Scanning
- Signed Artifacts
- Least Privilege
- Secrets Management
Production Scenarios
29. A build fails because of a critical vulnerability. What would you do?
Steps
- Review Scan Report
- Identify CVE
- Upgrade Dependency
- Rebuild
- Verify Results
30. Container image contains critical vulnerabilities.
How do you fix it?
- Update Base Image
- Remove Unused Packages
- Upgrade Dependencies
- Scan Again
- Redeploy
31. Developer accidentally committed AWS credentials to GitHub.
What are your immediate actions?
- Revoke Credentials
- Rotate Keys
- Remove Secret from Repository History
- Investigate Access Logs
- Enable Secret Scanning
32. Kubernetes deployment was rejected.
Possible reasons
- OPA Policy
- Kyverno Validation
- Missing Labels
- Security Context Violation
- Resource Limits Missing
33. Application passed SAST but failed DAST.
Why?
Because
SAST checks source code.
DAST tests runtime behavior.
34. Production container unexpectedly opened a shell.
How would you investigate?
- Falco Alerts
- Kubernetes Audit Logs
- Container Logs
- User Activity
- SIEM Events
35. How would you design a secure enterprise CI/CD pipeline?
flowchart LR
Developer --> GitHub --> CodeReview --> SAST --> SCA --> IaCScan --> ContainerScan --> SBOM --> Cosign --> Registry --> ArgoCD --> Kubernetes --> Falco --> SIEM
Common DevSecOps Tools
| Category | Tool |
|---|---|
| Source Control | GitHub |
| CI/CD | Jenkins |
| SAST | SonarQube |
| DAST | OWASP ZAP |
| SCA | Snyk |
| Secrets | Vault |
| Container Scan | Trivy |
| IaC Scan | Checkov |
| Policy | OPA |
| Kubernetes Policy | Kyverno |
| Runtime Security | Falco |
| Image Signing | Cosign |
| GitOps | Argo CD |
| SIEM | Splunk |
| SOAR | Cortex XSOAR |
Production Best Practices
- Shift Security Left
- Secure Coding Standards
- Scan Every Pull Request
- Scan Dependencies
- Scan Infrastructure as Code
- Scan Container Images
- Use Signed Images
- Encrypt Secrets
- Enable Runtime Monitoring
- Automate Incident Response
- Continuously Patch Vulnerabilities
Real-World Example
A banking application is deployed to Amazon EKS.
Workflow
- Developers submit code to GitHub.
- Pull Requests trigger SonarQube SAST and Snyk dependency scanning.
- Terraform templates are validated with Checkov.
- Docker images are scanned with Trivy.
- An SBOM is generated and the image is signed using Cosign.
- Argo CD deploys only verified images to Kubernetes.
- OPA Gatekeeper validates admission policies.
- Falco detects suspicious runtime activity and forwards alerts to Splunk Enterprise Security.
- SOAR automatically opens an incident ticket and notifies the security operations team.
Quick Revision Cheat Sheet
| Topic | Key Point |
|---|---|
| DevSecOps | Security in SDLC |
| Shift Left | Early Security |
| SAST | Static Code Analysis |
| DAST | Runtime Testing |
| SCA | Dependency Scanning |
| Secrets | Vault |
| IaC Security | Checkov |
| Container Security | Trivy |
| Policy as Code | OPA |
| Kubernetes Policy | Kyverno |
| Image Signing | Cosign |
| SBOM | Software Inventory |
| Runtime Security | Falco |
| Zero Trust | Never Trust, Always Verify |
| SIEM | Security Monitoring |
| SOAR | Automated Response |
Interview Tips
Remember these keywords
- DevSecOps
- Shift Left
- Secure SDLC
- SAST
- DAST
- SCA
- OWASP Top 10
- Secrets Management
- Container Security
- IaC Security
- SBOM
- Cosign
- OPA
- Kyverno
- Falco
- Zero Trust
- SIEM
- SOAR
Summary
DevSecOps interviews focus on integrating security into every stage of software delivery rather than treating security as a separate activity. Interviewers expect candidates to understand secure CI/CD pipelines, automated security testing, software supply chain security, Kubernetes security, runtime protection, policy enforcement, and cloud security.
Hands-on experience with SonarQube, Snyk, Trivy, Checkov, Vault, OPA, Kyverno, Cosign, Falco, Splunk, and Argo CD will significantly strengthen your ability to solve enterprise security challenges and succeed in DevOps, Platform Engineering, Cloud Engineering, Security Engineering, SRE, and Solution Architect interviews.