Q: Your team manages an AWS account. An auditor demands to know precisely who deleted a critical S3 bucket yesterday at 14:00. Where do you find this information, and what specific data points are you looking for?
I would query AWS CloudTrail, which logs all API activity within the AWS account.
#General DevOps #General DevOps — Scenario-Based Interview Questions #L3 #DevOps #SRE #Architecture
🎙️ Candidate Opening & Architectural Context
""In our engineering organization, DevOps culture meant aligning developer speed with site reliability. The interviewer is testing: AWS CloudTrail, event logging analysis.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
I would query AWS CloudTrail, which logs all API activity within the AWS account.
userIdentity.arn(Who did it? e.g., an IAM Userarn:aws:iam::123:user/bobor an assumed role).eventName(e.g.,DeleteBucket).sourceIPAddress(Where did the API call originate from? Corporate VPN, or Russian IP space?).
2️⃣
Remediation & Permanent Safeguards
I can query it via the AWS Console CloudTrail Event History, using AWS Athena if the logs are backed to S3, or via CLI: aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=DeleteBucket The critical data points I'm extracting from the JSON log are:
requestParameters.bucketName(To confirm it's the exact bucket).
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: userIdentity.arn (Who did it? e.g., an IAM User arn:aws:iam::123:user/bob or an assumed role).."
⚡ 60-Second Elevator Pitch Talking Points
- userIdentity.arn (Who did it? e.g., an IAM User arn:aws:iam::123:user/bob or an assumed role).
- eventName (e.g., DeleteBucket).
- sourceIPAddress (Where did the API call originate from? Corporate VPN, or Russian IP space?).
Advertisement