DevSecOps Interview Questions

Top DevSecOps interview questions and answers covering Secure SDLC, Shift Left Security, SAST, DAST, SCA, Container Security, Kubernetes Security, Supply Chain Security, SBOM, Zero Trust, SIEM, SOAR, and enterprise production scenarios.

Introduction

DevSecOps has become one of the most important skills for modern DevOps Engineers, Platform Engineers, Cloud Engineers, Security Engineers, SREs, and Solution Architects.

Interviewers expect candidates to understand not only security tools but also how security integrates throughout the software development lifecycle, CI/CD pipelines, Kubernetes platforms, cloud environments, and production systems.

This guide contains the most frequently asked enterprise DevSecOps interview questions.


Enterprise DevSecOps Architecture

flowchart LR

Developer --> GitHub --> CI

CI --> SAST

CI --> SCA

CI --> ContainerScan

CI --> IaCScan

CI --> ImageSigning

CI --> Registry

Registry --> ArgoCD

ArgoCD --> Kubernetes

Kubernetes --> Falco

Falco --> SIEM

SIEM --> SOC

DevSecOps Basics


1. What is DevSecOps?

Answer

DevSecOps integrates security into every phase of software development and operations.

Instead of performing security only before production deployment, security becomes part of

  • Development
  • Build
  • Testing
  • Deployment
  • Runtime
  • Monitoring

2. Why is DevSecOps important?

Benefits

  • Early Vulnerability Detection
  • Faster Releases
  • Reduced Risk
  • Automated Security
  • Better Compliance
  • Lower Cost

3. Difference between DevOps and DevSecOps?

DevOps DevSecOps
Automation Secure Automation
Faster Delivery Secure Delivery
Security Later Security Everywhere
Shared Operations Shared Security Responsibility

Shift Left Security


4. What is Shift Left Security?

Security activities are performed earlier in the SDLC.

Examples

  • Secure Coding
  • SAST
  • Dependency Scanning
  • Secret Detection

Benefits

  • Faster Fixes
  • Lower Cost
  • Better Security

Secure SDLC


5. What is Secure SDLC?

Secure SDLC integrates security into every software development phase.

flowchart LR

Planning --> Design --> Development --> Testing --> Deployment --> Monitoring

Security activities include

  • Threat Modeling
  • Secure Coding
  • Security Testing
  • Monitoring

Security Testing


6. What is SAST?

Static Application Security Testing analyzes source code without executing the application.

Finds

  • SQL Injection
  • XSS
  • Hardcoded Secrets
  • Insecure Coding Patterns

Popular Tools

  • SonarQube
  • Checkmarx
  • Semgrep
  • Fortify

7. What is DAST?

Dynamic Application Security Testing scans a running application.

Finds

  • Authentication Issues
  • Runtime Vulnerabilities
  • API Security Problems

Popular Tools

  • OWASP ZAP
  • Burp Suite

8. Difference between SAST and DAST?

SAST DAST
Source Code Running Application
Early SDLC After Deployment
White Box Black Box
Fast Feedback Runtime Testing

9. What is SCA?

Software Composition Analysis scans third-party libraries.

Detects

  • Vulnerable Dependencies
  • License Issues
  • Outdated Packages

Popular Tools

  • Snyk
  • Dependabot
  • Mend
  • OWASP Dependency-Check

Secrets Management


10. Why should secrets never be stored in Git?

Because repositories may expose

  • Passwords
  • API Keys
  • Tokens
  • Certificates

Use

  • HashiCorp Vault
  • AWS Secrets Manager
  • Azure Key Vault

Container Security


11. How do you secure Docker images?

Best Practices

  • Minimal Base Images
  • Scan Images
  • Run as Non-root
  • Remove Unused Packages
  • Sign Images

12. Which tools scan container images?

Examples

  • Trivy
  • Grype
  • Clair

Infrastructure Security


13. What is IaC Security?

Infrastructure as Code templates are scanned before deployment.

Checks

  • Public Storage Buckets
  • Open Security Groups
  • Weak IAM Policies
  • Encryption Disabled

Tools

  • Checkov
  • tfsec
  • Terrascan

Kubernetes Security


14. How do you secure Kubernetes?

Security Areas

  • RBAC
  • Network Policies
  • Secrets
  • Admission Controllers
  • Runtime Monitoring

15. What are Admission Controllers?

Admission Controllers validate requests before Kubernetes creates resources.

Examples

  • Gatekeeper
  • Kyverno

Policy as Code


16. What is Policy as Code?

Policies are written as code and automatically enforced.

Benefits

  • Automation
  • Compliance
  • Governance
  • Consistency

17. What is OPA?

Open Policy Agent validates security rules.

Example Policies

  • No Privileged Containers
  • Mandatory Labels
  • Resource Limits

18. Difference between OPA and Kyverno?

OPA Kyverno
General Policy Engine Kubernetes Native
Uses Rego Uses YAML
Flexible Easier Learning

Supply Chain Security


19. What is Software Supply Chain Security?

Protects

  • Source Code
  • Dependencies
  • Build Pipelines
  • Container Images
  • Registries

Goal

Only trusted software reaches production.


20. What is SBOM?

Software Bill of Materials.

Contains

  • Dependencies
  • Versions
  • Licenses
  • Components

Benefits

  • Compliance
  • Faster CVE Response
  • Supply Chain Visibility

21. What is Image Signing?

Digitally signs container images.

Benefits

  • Integrity
  • Authenticity
  • Tamper Detection

Popular Tool

  • Cosign

Runtime Security


22. What is Runtime Security?

Protects applications after deployment.

Detects

  • Container Escape
  • Privilege Escalation
  • Reverse Shells
  • Suspicious Processes

23. What is Falco?

Falco monitors Linux kernel events.

Detects

  • Shell Access
  • File Modifications
  • Privilege Escalation
  • Container Escape

Zero Trust


24. What is Zero Trust?

Security model based on

"Never Trust, Always Verify"

Principles

  • Identity Verification
  • Least Privilege
  • Continuous Authentication

Cloud Security


25. Which cloud security services have you used?

AWS

  • IAM
  • GuardDuty
  • Security Hub
  • Inspector
  • KMS

Azure

  • Defender for Cloud

Google Cloud

  • Security Command Center

SIEM & SOAR


26. What is SIEM?

Security Information and Event Management.

Collects

  • Logs
  • Events
  • Alerts
  • Audit Data

Examples

  • Splunk
  • Microsoft Sentinel
  • IBM QRadar

27. What is SOAR?

Security Orchestration, Automation and Response.

Automates

  • Incident Response
  • Alert Correlation
  • Ticket Creation
  • Threat Investigation

CI/CD Security


28. How do you secure a CI/CD pipeline?

Best Practices

  • Code Reviews
  • SAST
  • SCA
  • IaC Scanning
  • Image Scanning
  • Signed Artifacts
  • Least Privilege
  • Secrets Management

Production Scenarios


29. A build fails because of a critical vulnerability. What would you do?

Steps

  • Review Scan Report
  • Identify CVE
  • Upgrade Dependency
  • Rebuild
  • Verify Results

30. Container image contains critical vulnerabilities.

How do you fix it?

  • Update Base Image
  • Remove Unused Packages
  • Upgrade Dependencies
  • Scan Again
  • Redeploy

31. Developer accidentally committed AWS credentials to GitHub.

What are your immediate actions?

  • Revoke Credentials
  • Rotate Keys
  • Remove Secret from Repository History
  • Investigate Access Logs
  • Enable Secret Scanning

32. Kubernetes deployment was rejected.

Possible reasons

  • OPA Policy
  • Kyverno Validation
  • Missing Labels
  • Security Context Violation
  • Resource Limits Missing

33. Application passed SAST but failed DAST.

Why?

Because

SAST checks source code.

DAST tests runtime behavior.


34. Production container unexpectedly opened a shell.

How would you investigate?

  • Falco Alerts
  • Kubernetes Audit Logs
  • Container Logs
  • User Activity
  • SIEM Events

35. How would you design a secure enterprise CI/CD pipeline?

flowchart LR

Developer --> GitHub --> CodeReview --> SAST --> SCA --> IaCScan --> ContainerScan --> SBOM --> Cosign --> Registry --> ArgoCD --> Kubernetes --> Falco --> SIEM

Common DevSecOps Tools

Category Tool
Source Control GitHub
CI/CD Jenkins
SAST SonarQube
DAST OWASP ZAP
SCA Snyk
Secrets Vault
Container Scan Trivy
IaC Scan Checkov
Policy OPA
Kubernetes Policy Kyverno
Runtime Security Falco
Image Signing Cosign
GitOps Argo CD
SIEM Splunk
SOAR Cortex XSOAR

Production Best Practices

  • Shift Security Left
  • Secure Coding Standards
  • Scan Every Pull Request
  • Scan Dependencies
  • Scan Infrastructure as Code
  • Scan Container Images
  • Use Signed Images
  • Encrypt Secrets
  • Enable Runtime Monitoring
  • Automate Incident Response
  • Continuously Patch Vulnerabilities

Real-World Example

A banking application is deployed to Amazon EKS.

Workflow

  1. Developers submit code to GitHub.
  2. Pull Requests trigger SonarQube SAST and Snyk dependency scanning.
  3. Terraform templates are validated with Checkov.
  4. Docker images are scanned with Trivy.
  5. An SBOM is generated and the image is signed using Cosign.
  6. Argo CD deploys only verified images to Kubernetes.
  7. OPA Gatekeeper validates admission policies.
  8. Falco detects suspicious runtime activity and forwards alerts to Splunk Enterprise Security.
  9. SOAR automatically opens an incident ticket and notifies the security operations team.

Quick Revision Cheat Sheet

Topic Key Point
DevSecOps Security in SDLC
Shift Left Early Security
SAST Static Code Analysis
DAST Runtime Testing
SCA Dependency Scanning
Secrets Vault
IaC Security Checkov
Container Security Trivy
Policy as Code OPA
Kubernetes Policy Kyverno
Image Signing Cosign
SBOM Software Inventory
Runtime Security Falco
Zero Trust Never Trust, Always Verify
SIEM Security Monitoring
SOAR Automated Response

Interview Tips

Remember these keywords

  • DevSecOps
  • Shift Left
  • Secure SDLC
  • SAST
  • DAST
  • SCA
  • OWASP Top 10
  • Secrets Management
  • Container Security
  • IaC Security
  • SBOM
  • Cosign
  • OPA
  • Kyverno
  • Falco
  • Zero Trust
  • SIEM
  • SOAR

Summary

DevSecOps interviews focus on integrating security into every stage of software delivery rather than treating security as a separate activity. Interviewers expect candidates to understand secure CI/CD pipelines, automated security testing, software supply chain security, Kubernetes security, runtime protection, policy enforcement, and cloud security.

Hands-on experience with SonarQube, Snyk, Trivy, Checkov, Vault, OPA, Kyverno, Cosign, Falco, Splunk, and Argo CD will significantly strengthen your ability to solve enterprise security challenges and succeed in DevOps, Platform Engineering, Cloud Engineering, Security Engineering, SRE, and Solution Architect interviews.