5yrs+ DevOps Engineer LIVE Interview. #

Sdílet
Vložit
  • čas přidán 14. 11. 2023
  • 💜 Booking link for Live AWS Bootcamp - Beginner to Advanced: topmate.io/cloud/649976
    💙 Booking link for Live Project # 3 Starting 14th Jan: topmate.io/cloud/649977
    💙 Booking link for Mentorship Program: topmate.io/cloud/606995
    ---------------------------------------------------
    💙 Join Our WhatsApp Group: chat.whatsapp.com/KdLU9U4zFXf...
    💚 Join Our Telegram Group: t.me/+xjZA3ZS-OQkxZTk1
    💜 Follow our community page on LinkedIn: / devops-and-cloud-labs
    ---------------------------------------------------
    💙 Booking link for Project # 1 Recordings: topmate.io/cloud/395820
    💙 Booking link for Project # 2 Recordings: topmate.io/cloud/453994
    💙 Booking link for DevOps Cloud Bootcamp (Recorded): topmate.io/cloud/555006
    ---------------------------------------------------
    💚 Subscribe to the Channel: / @devops-cloud
    devops
    devops interview questions
    devops engineer
    devops interview
    devops interview recordings
    aws devops interview questions
    devops engineer interview
    devops interview questions for 3 years experience
    devops mock interview
    aws interview
    devops interview questions for freshers
    cloud engineer interview questions
    devops interview questions for 2 years experience
    devops future scope
    cloud engineer interview
    devops fresher interview questions
    aws devops interview
    future of devops
    devops future
    devops fresher interview
    devops interviews
    devops interview for freshers
    devops mock interview for freshers
    interview devops
    aws cloud engineer mock interview
    senior devops engineer interview questions
    devops engineer future scope
    devops interview fresher
    cloud engineer mock interview
    cloud engineer fresher interview
    devops interview,devops,devops interview questions,devops engineer,devops engineer interview,devops interview recordings,aws interview questions,devops and cloud,DevOps Engineer,Cloud Engineer,Interview,DevOps Engineer Interview,Cloud Engineer Interview,AWS Interview,Junior Freshers Interview,devops mock interview,devops interview questions for experienced, DevOps Cloud, AWS Projects, DevOps projects for practice
    AWS
    Azure
    Terraform
    Infrastructure
    Kubernetes
    K8s
    Docker
    IaC, Infra as Code

Komentáře • 9

  • @mohammedjuneadsheriffz5304
    @mohammedjuneadsheriffz5304 Před 8 měsíci +10

    Only partial video shared, so far the interview was good. Looks like he has subject knowledge and knows what he’s telling. Full video sharing would have been better.
    I don’t know what he answered for 3tier app security. My answer would be front end in public subnet, DB and backend ec2 instances in private subnet. Connection establishment between public and private subnet through Bastion host or NAT gateway and the complete application in a vpc(2 AZ’s) for high availability. Clients/ users will be exposed to front end application through ALB which will be in public subnet and ALB will in turn communicate with resources in the private subnet. By having VPC and implementing NACL I am ensuring open access restrictions and by having DB and logic servers in private subnet I’m masking their IP from exposing to internet. Also, additional security layer will be applied to the instances and DB by configuring inbound rules security groups.

    • @DevOps-Cloud
      @DevOps-Cloud  Před 8 měsíci +9

      Unfortunately due to bad internet connectivity, the interview could not proceed further.
      Other interviews in the channel should be complete.
      Below are some of the aspects to be considered when answering securing an application in the cloud:
      Identity and Access Management (IAM):
      Use strong authentication mechanisms, such as Multi-Factor Authentication (MFA), for user accounts.
      Implement the principle of least privilege to ensure that users and services have the minimum required permissions.
      Network Security:
      Utilize Virtual Private Clouds (VPCs) to isolate resources logically.
      Set up network security groups or firewalls to control incoming and outgoing traffic.
      Consider using a Web Application Firewall (WAF) to protect against common web application attacks.
      Data Encryption:
      Encrypt data in transit using protocols like TLS/SSL.
      Encrypt data at rest using services provided by the cloud provider or third-party tools.
      Manage encryption keys securely using Key Management Services.
      Regular Updates and Patch Management:
      Keep all software, including the operating system, web servers, databases, and application dependencies, up to date with the latest security patches.
      Monitoring and Logging:
      Set up logging and monitoring to detect and respond to security incidents.
      Use cloud provider services for monitoring, and consider third-party tools for enhanced visibility.
      Incident Response Plan:
      Develop an incident response plan to handle security breaches and unexpected incidents.
      Regularly test and update the incident response plan.
      Security Groups and Policies:
      Implement security groups, network ACLs, and security policies to control traffic between different components of your application.
      Define and enforce security policies that align with industry compliance standards.
      Container Security:
      If using containers, ensure the images are scanned for vulnerabilities.
      Employ container orchestration tools (e.g., Kubernetes) with security best practices.
      Backup and Disaster Recovery:
      Regularly back up critical data and ensure that a reliable disaster recovery plan is in place.
      Test the backup and recovery procedures periodically.
      API Security:
      Secure APIs with authentication and authorization mechanisms.
      Use OAuth or API keys for access control and ensure that sensitive information is not exposed in API responses.
      Compliance and Auditing:
      Understand and comply with industry-specific regulations and standards.
      Regularly conduct security audits and assessments.
      Security Training:
      Train your development, operations, and support teams on security best practices.
      Create awareness about common security threats and social engineering attacks.
      Third-Party Services Security:
      If using third-party services, ensure they follow security best practices.
      Regularly review and update permissions and configurations for third-party services.
      Regular Security Assessments:
      Conduct regular security assessments, including penetration testing and vulnerability scanning, to identify and address potential security issues.

  • @yashsingh7042
    @yashsingh7042 Před 8 měsíci +1

    These interviews videos are really helping us.Please do come up with more scenario based interviews in near future. Cheers

  • @jjajebit4820
    @jjajebit4820 Před 3 měsíci +4

    Guru , could you please consider to do an evaluation of the interview process and adding some details that were missed? The last question you asked about security of a 3-tier application , his answer didn’t go that deep.

  • @jjajebit4820
    @jjajebit4820 Před 3 měsíci +2

    Learning a lot from your style of interviewing . Good job and thank you .

  • @owenzmortgage8273
    @owenzmortgage8273 Před 8 měsíci +4

    Cheapest 🎤 microphone makes bad quality audio

  • @vvalerka6981
    @vvalerka6981 Před 5 měsíci +2

    an accent is very bad I could not really understand.

    • @zh85
      @zh85 Před 4 měsíci +1

      Indian Accents in IT in USA is appreciated !!! We love our indian dudes who are smart as hell with a bit of hard to understand but get the job done :)