Skip to content

Enterprise Architect interview questions

100 real questions with model answers and explanations for Senior Enterprise Architect candidates.

See a Enterprise Architect resume example

Practice with flashcards

Spaced repetition · Hunter Pass

Questions

ownership

I would build a confidence-scored portfolio baseline before recommending any transformation waves.

  • Import CMDB, finance, IAM, and network-flow data into LeanIX, then reconcile each application to an owner, annual run cost, lifecycle state, and business capability.
  • Rank the 840 records by spend and risk, using architect interviews only for the top 200 while automated evidence covers the long tail.
  • Mark facts with high, medium, or low confidence and block retirement decisions where identity, data-retention, or downstream dependencies remain low confidence.
  • Deliver a heatmap showing cost, technical health, business criticality, and confidence, not a falsely precise inventory that takes a year to complete.

Why interviewers ask this: The interviewer is testing whether you can turn incomplete portfolio data into bounded, auditable decisions without delaying all action.

roadmap

I would fund coherent capability outcomes rather than divide the $40M proportionally among sponsors.

  • Score proposals on revenue or cost impact, regulatory deadline, operational risk, architecture fit, and delivery confidence, with each score backed by a named metric.
  • Reserve about $8M for mandatory controls and obsolescence, then compare the remaining work by risk-adjusted NPV and cost of delay.
  • Use Planview for financial scenarios and LeanIX for application dependencies so a $3M front-end proposal does not ignore a required $6M core-system change.
  • Present a funded portfolio plus a ranked cut line, including which benefits and risks move if the budget drops to $30M or rises to $50M.

Why interviewers ask this: A strong answer connects portfolio economics to architecture dependencies and makes the consequences of the funding boundary explicit.

roadmapapionboarding

I would make the two platform capacity dates the product critical path and fund them before committing all four regional launches.

  • Build one dependency roadmap linking each regional journey to identity onboarding, data contracts, API certification, capacity slots, and the accountable platform owner.
  • Fund reusable identity and data enablers only against named regional releases, with reserved platform capacity and delivery dates accepted by both teams.
  • Put stop gates at contract certification, regional load test, and launch readiness; a missed hard dependency moves that region rather than creating an unapproved bypass.
  • Review the critical path every two weeks and show the sponsor which revenue date, scope, or extra capacity must change when a platform commitment slips.

Why interviewers ask this: The interviewer is checking whether you can turn scarce shared-platform capacity into a funded critical path with credible stop decisions.

onboardingsystem-design

I would map the 47 systems to the onboarding value stream and fund the bottlenecks that drive the 18-day lead time.

  • Use ArchiMate capability and value-stream views to connect each journey stage to applications, data owners, manual handoffs, and annual run cost.
  • Measure queue time and rework at each stage, which may show that a two-day credit decision is less important than nine days waiting for document verification.
  • Target investment at shared capabilities such as identity proofing and customer master data instead of replacing four division portals independently.
  • Baseline lead time, straight-through-processing rate, and cost per onboarding so the roadmap is accountable for business outcomes, not diagram completion.

Why interviewers ask this: This tests whether capability models lead to measurable investment choices rather than becoming static documentation.

system-design

I would separate structural savings from indiscriminate cuts and protect controls tied to regulated processes.

  • Reconcile contracts and cloud bills to LeanIX, then cluster duplicate CRM, reporting, integration, and document-management products by capability.
  • Prioritize contracts renewing within 12 months, applications with fewer than 50 active users, and technologies already out of vendor support.
  • Validate every candidate against data retention, legal hold, segregation-of-duties, and business-continuity obligations before booking savings.
  • Offer finance a gross pipeline above $25M because migration, termination, and dual-run costs will reduce first-year net savings toward the $18M target.

Why interviewers ask this: The interviewer is evaluating whether you can find credible portfolio savings while accounting for exit costs and control obligations.

roadmap

I would withhold the next tranche from any initiative that cannot enter a finance-owned benefits ledger before the committee.

  • Give each initiative a baseline, target, calculation formula, evidence source, realization date, and one business owner who can change the process that creates the benefit.
  • Separate cashable savings, cost avoidance, revenue, risk reduction, and service outcomes so unlike claims are not added into one headline number.
  • Release funding by outcome gates, with the first gate proving the baseline and the next showing adoption or an invoice, cycle-time, or control movement attributable to the initiative.
  • Report forecast and realized benefits separately each quarter, and stop or reshape work whose owner cannot explain the variance with finance evidence.

Why interviewers ask this: A strong answer makes benefits measurable and owned before funding rather than accepting unsupported roadmap claims.

architecture

I would standardize enterprise capabilities and contracts while preserving justified division variation behind them.

  • Run domain workshops to define shared bounded contexts such as Customer, Offer, Order, and Fulfillment, with one accountable owner for each enterprise contract.
  • Produce an ArchiMate target view that separates global platforms from division components and records variation drivers such as regulation, channel, or latency.
  • Mandate common identity, event schemas, observability, and customer identifiers while allowing a division-specific fulfillment engine where economics support it.
  • Set a three-year transition path with measurable convergence points instead of drawing a single end-state box that ignores current commitments.

Why interviewers ask this: The interviewer is testing whether you can create cross-divisional coherence without confusing standardization with identical implementations.

soft-skillsjoinsarchitecture

I would treat the fifth division as a test of the target architecture's explicit variation model, not grant a blanket exception.

  • Trace the 120 ms budget through gateway, identity, service, and data hops using OpenTelemetry evidence rather than assuming the shared platform is too slow.
  • Keep regulated records in the local region and expose approved aggregates or tokens through the enterprise data contract.
  • Extend the reference architecture with a regional deployment pattern if at least two use cases share it; otherwise record a time-bound ADR for this division.
  • Reprice the target because regional replicas, key management, and support may add $1.2M annually even when the logical architecture stays common.

Why interviewers ask this: This assesses whether you can absorb concrete divisional constraints through governed variation and quantified cost.

architecture

I would make the mainframe a temporary system of record behind the new enterprise contracts rather than wait four years for full convergence.

  • Put versioned customer APIs behind Kong and publish change events through Kafka using a CDC tool such as Debezium where transaction semantics permit it.
  • Add an anti-corruption layer so COBOL record layouts and division codes do not leak into the target customer model.
  • Move read-heavy journeys to the new customer platform first, then migrate write ownership by customer segment with reconciliation controls.
  • Give every bridge an owner, throughput limit, retirement trigger, and no-later-than date so transitional integration does not become permanent architecture.

Why interviewers ask this: The interviewer wants a concrete bridge from legacy constraints to target ownership, including controls that prevent the bridge from becoming permanent.

architecture

I would design one capability with explicit service tiers rather than force every division to pay for 99.99%.

  • Define bronze and critical tiers with concrete SLOs, RTO, RPO, support hours, and transaction limits in the service contract.
  • Use the same payment API and event schema, but give the critical tier multi-region deployment and stricter dependency budgets.
  • Charge the additional resilience cost to consumers selecting the critical tier, making the estimated $2M annual premium visible.
  • Test both tiers with automated recovery exercises and publish error-budget performance so divisions choose based on evidence, not preference.

Why interviewers ask this: A strong answer translates different divisional needs into a shared architecture with transparent service and cost tiers.

I would move a bounded portion of funding from temporary projects to the persistent claims value stream with outcome controls.

  • Map claim intake through settlement, then assign one business and one technology owner to the full value stream rather than six local project sponsors.
  • Give the value stream a 12-month envelope tied to cycle time, straight-through-processing, leakage, and customer-contact targets.
  • Fund shared platforms separately where more than three value streams consume them, with a published allocation formula instead of hiding platform cost in claims.
  • Start with 20% of discretionary spend for two quarters, because changing all 70 projects at once would overwhelm finance controls and delivery governance.

Why interviewers ask this: The interviewer is checking whether you can make value-stream funding operational through ownership, metrics, and a controlled transition.

I would split identity funding into a strategic base and a usage-driven variable charge.

  • Fund core controls, platform engineering, and minimum resilience centrally because every value stream benefits even at low transaction volume.
  • Allocate variable cost by active identities, authentication volume, and premium features such as step-up verification, using FinOps data rather than headcount alone.
  • Publish unit costs and service tiers in Backstage so a value stream can see the cost of choosing 99.99% availability or SMS MFA.
  • Review the formula twice yearly because aggressive chargeback can drive teams to duplicate identity solutions and increase enterprise risk.

Why interviewers ask this: This tests whether shared-platform economics can be made transparent without creating incentives for architectural fragmentation.

budget

I would replace project-gate control with quarterly outcome and architecture guardrails, not remove accountability.

  • Give each capability a rolling roadmap with two business measures, one reliability SLO, and unit economics such as cost per order or policy change.
  • Release funding quarterly against evidence from OKRs, benefits ledgers, and delivery forecasts rather than percent-complete reports.
  • Require ADRs and automated policy checks for decisions that affect regulated data, enterprise contracts, or annual run cost above $500K.
  • Stop or reshape a capability when two quarters miss outcomes without validated learning, while preserving persistent teams that are meeting service obligations.

Why interviewers ask this: The interviewer wants a specific operating model that preserves executive control while allowing persistent capability ownership.

sponsorarchitecture

I would reject a full TOGAF document set and ask the sponsor to approve four decision outputs for the 90-day window.

  • By day 15, deliver one scope and architecture-vision brief with the business outcomes, regulated boundaries, named decision owners, and explicit out-of-scope capabilities.
  • By day 45, deliver one joined baseline, target, and transition view covering only the value streams, systems, data, and dependencies changed by the $30M program.
  • By day 75, deliver one dependency roadmap and one linked decision register containing work packages, risks, controls, ADRs, owners, and stop conditions.
  • The transformation committee signs scope at day 30 and target choices at day 60; internal audit samples control traceability at day 90 before the next funding gate, with no full ADM catalog or enterprise-wide model in scope.

Why interviewers ask this: The interviewer is evaluating whether you can make a firm, auditable 90-day architecture commitment without turning TOGAF into paperwork.

architecture

I would use the official Zachman rows and columns only to classify existing evidence and expose material gaps.

  • Index artifacts by What, How, Where, Who, When, and Why across the official Scope Contexts, Business Concepts, System Logic, Technology Physics, Component Assemblies, and Operations Instances rows.
  • Start with 20 regulated applications and link each classified artifact to its source, owner, version, control, and retention evidence in the repository.
  • I would not invent auditor or operator perspectives, speculate into empty cells, or create an artifact merely to make the matrix look complete.
  • Auditors review the sample by day 30, the architecture committee accepts material gap owners by day 60, and internal audit resamples at day 90 before the pattern is scaled.

Why interviewers ask this: A strong answer uses Zachman accurately as an artifact-classification schema with explicit audit gates, not as a framework lecture or operating model.

I would take one recommendation and three ArchiMate views to the committee, not walk executives through the repository.

  • The recommendation memo states which operating model I choose, the two decisive assumptions, the quantified downside, and the decision that cannot be delegated.
  • A capability and value-stream view shows central versus division ownership and the customer outcomes affected by each option.
  • An application-cooperation view shows shared platforms, trust boundaries, and duplicate responsibilities, while an implementation view shows the 24-month dependencies and transition states.
  • Low-level objects and unrelated domains stay excluded; the committee decides by day 30, architecture assurance checks the chosen trace at day 60, and internal audit samples decision-to-control evidence by day 90 before funding proceeds.

Why interviewers ask this: The interviewer is checking whether you can make a clear executive recommendation with no more than four outputs and enforce decision and audit gates.

ci-cd

I would agree exactly what the 50% measures, then reduce concentration in the critical functions that drive that denominator.

  • Put only ICT third-party arrangements and their contracts, services, locations, substitutability, and exit obligations in the DORA register; keep internal workload dependencies in the architecture repository.
  • Have the board and risk function sign one primary denominator, such as provider spend supporting critical functions, and report workload share and revenue at risk separately rather than mixing them.
  • Move selected customer or analytics domains and establish an independently recoverable CI/CD path only where they materially reduce the agreed concentration measure.
  • Review the signed numerator and denominator quarterly, with tested recovery and residual outage loss beside the percentage so a cosmetic workload move cannot claim compliance.

Why interviewers ask this: The interviewer is testing whether you apply DORA to ICT third parties and measure a board ceiling with an explicit, defensible denominator.

databasedesign

I would agree the required exit scope with the regulator and treat partial rehearsals as progress, not proof of a full provider exit.

  • Define the full test as the regulator-agreed critical journeys, data volume, identities, keys, operations, RTO, RPO, and permitted degraded functions across all in-scope services.
  • Build open-format exports, schema conversion, alternate infrastructure, external runbooks, and contract rights first for the proprietary database and other hard-to-replace state.
  • Run progressive tests from export and restore, to one journey at 20% volume, to the full agreed scope; record each stage as partial until the final exercise passes.
  • If cost or safety prevents the full test, obtain explicit regulatory acceptance of the reduced scope and residual risk rather than calling a 20% rehearsal complete exit evidence.

Why interviewers ask this: A strong answer distinguishes progressive exit evidence from full proof and makes the regulator the authority for any reduced test scope.

procurementcloudcloud-models

I would assign continuity tiers to the affected journeys and prove exports and manual modes before buying duplicate SaaS platforms.

  • Map the 65% to named journeys and classify identity, CRM, and collaboration dependencies by maximum outage, data-loss tolerance, and feasible manual duration.
  • Contract tested exports of identities, CRM records, configurations, and audit evidence at a cadence tied to each tier, storing recovery copies outside the vendor failure boundary.
  • Rehearse vendor loss with break-glass identity, queued customer updates, approved offline contact records, and a collaboration call tree, stating user, country, and duration limits.
  • Escalate a tier when a test misses its recovery target or one vendor gains more critical journeys; use a replacement or manual route unless active-active economics are actually justified.

Why interviewers ask this: The interviewer is evaluating whether you manage SaaS concentration through tiered, tested continuity rather than an unrealistic duplicate-cloud design.

I would reject universal portability and sign three tiers within ten days so the 60-day evidence focuses on material provider-exit risk.

  • Tier 1 covers regulator-agreed critical journeys and requires tested redeployment, recoverable data, external keys and artifacts, and named substitutes for proprietary services.
  • Tier 2 requires verified exports and a costed replatform plan, while Tier 3 may accept lock-in with an owner, exit estimate, and review trigger.
  • Product leaders can keep native services outside Tier 1, but must show the avoided $8M cost and the outage exposure accepted by the business risk owner.
  • Before the regulator meeting, test one Tier 1 journey end to end and report failed controls honestly; misclassifying a critical service blocks its launch rather than weakening the tier.

Why interviewers ask this: The interviewer is checking whether you resolve a costly portability dispute by a deadline with a concrete scope and consequence for error.

Locked questions

  • 21

    Your technology radar lists 65 items, but teams treat it as opinion and ignore it; how would you make the next quarterly radar evidence-based?

  • 22

    A vendor asks the CTO to place its new generative AI platform directly in Adopt after a six-week pilot with one team; what evidence would you require?

    procurementdecision-making
  • 23

    A database marked Hold on the radar still supports 75 applications, and its vendor ends support in 30 months; how would you turn the radar decision into action?

    procurementdatabase
  • 24

    Architecture observability for 1,200 services shows runtime calls that disagree with approved contracts and SLO diagrams, but the team does not want another CMDB cleanup; what would you build?

    sloobservabilityconflict
  • 25

    A reference architecture bans direct database access across domains, yet 140 teams produce hundreds of changes each week; how would you implement a fitness function?

    databasearchitecture
  • 26

    Security requires all 900 APIs to use approved authentication and TLS settings, but manual architecture reviews cover only 5% of releases; what would you automate?

    authtlsarchitecture
  • 27

    The CTO asks for one monthly architecture-health metric across 120 teams; what would you report without creating a vanity score?

    monitoring
  • 28

    Central architecture wants one API gateway for five divisions, but two regulated divisions need local products; a partner launch is due in 60 days and another month of deadlock costs $3M, so who decides what?

    gatewayapi-gatewayapi
  • 29

    One of 110 teams needs to violate the approved data-store standard for a product launch in eight weeks; how would your exception process work?

    concurrencyerror-handling
  • 30

    Four divisions are issuing conflicting encryption exceptions before a regulation takes effect in 90 days; how would you delegate decisions without producing four control regimes?

    encryptionerror-handlingdelegation
  • 31

    Two division architects disagree over ownership of the Customer domain, delaying a shared platform by three months; how would you resolve the design decision?

    conflictownershipdesign
  • 32

    Before any build starts, an internal platform requests $12M for 120 teams but only 25 teams have confirmed adoption; what funding decision do you make?

    decision-making
  • 33

    A payment API must launch in 75 days across Java, .NET, and Node.js; security wants one mandated framework, stack leads estimate that rewrite at $2M, and a control gap could stop the launch, so what do you standardize?

    estimationapi
  • 34

    Before launching a platform golden path for 70 teams, research shows 80% of committed demand falls into three workload types; which archetypes and non-goals do you choose?

  • 35

    A retailer wants to replace a monolithic commerce suite before its license rises by $7M in 30 months; how would you design a composable target?

    monolithdesignmicroservices
  • 36

    A composable insurance platform proposal contains 38 independently deployable components for eight delivery teams; how would you assess whether it is over-decomposed?

    componentsdeployment
  • 37

    A vendor's composable platform exposes APIs but requires its workflow engine and proprietary event format for every component; how would you evaluate the lock-in before a $15M purchase?

    procurementcomponentsapi
  • 38

    An enterprise has 17 ESBs, 2,400 point-to-point interfaces, and a five-year modernization window; what integration-mesh target would you propose?

    types
  • 39

    Six domains publish 300 events, but consumers cannot tell which are authoritative and breaking changes are common; how would you govern the enterprise event mesh?

    versioning
  • 40

    A logistics company must connect 200 modern APIs, 600 nightly files, and 40 partner EDI links; how would you avoid forcing all integration through one pattern?

    api
  • 41

    Five divisions propose 30 data products, but the budget can support only eight next year; how do you choose which products receive funding?

  • 42

    A Customer data product serves 35 teams, but each defines active customer differently; how would you set its contract without centralizing every analytic definition?

  • 43

    A federated global data catalog contains conflicting classifications for 400 datasets across EU, US, and Singapore regions; how do you establish authority without moving raw data?

    classificationcloud-regions
  • 44

    Your company may acquire a $600M payments firm with 180 applications, 70 engineers, and a six-year-old PCI platform; what architecture due diligence would you complete in four weeks?

    architecture
  • 45

    An acquisition has closed, and the transitional service agreement for identity, network, and file exchange expires in 120 days; 2,400 users and 35 applications depend on it. How do you sequence the Day-120 exit?

  • 46

    You must sequence a $35M modernization portfolio covering a mainframe, 14 integration hubs, and 220 applications over three years; where do you start?

  • 47

    A $50M modernization proposal promises $18M annual savings but requires four years of dual running across 300 applications; how would you test the business case?

    budgetpromises
  • 48

    A financial platform must serve EU and Middle East customers, keep regulated records in-region, and still provide group-wide fraud detection within five minutes; what architecture would you propose?

    cloud-regions
  • 49

    Six project-based product teams hand their services to a central operations group; change lead time is 21 days, and 40% of severity-1 incidents cite ownership handoffs. How do you redesign the product operating model?

    incidentsownershipseverity-priority
  • 50

    The executive committee must choose how to modernize an order platform: a $12M containment option, a $28M phased replacement, or a $46M full transformation; how would you present the choice?

  • 51

    An acquisition leaves a $6B company with three ERP platforms across 42 countries; duplicate supplier records are causing a 7% invoice mismatch, but Day 1 is in 90 days and order entry cannot stop. What do you do first?

  • 52

    Two merged companies have 85,000 workers in Okta and Microsoft Entra ID; 1,400 duplicate identities include 63 privileged accounts, and the SOX remediation window is 30 days with no company-wide password reset allowed. How do you respond?

    passwords
  • 53

    After a merger, the board revenue report differs by 11% across three lakehouses, raw regional data must stay local, and the signed report is due in 60 days; what do you do?

    cloud-regions
  • 54

    Post-acquisition discovery finds 1,400 applications, two identity stacks, three ERPs, and four analytics platforms; executives expect $12M annual synergy in 18 months, but Year 1 integration funding is capped at $4M and business units reject a big-bang change. How do you sequence the work?

  • 55

    A four-hour AWS us-east-1 outage takes down services responsible for 70% of revenue; Route 53 failover works, but the secondary database is 47 minutes behind, and the contractual RTO is 30 minutes with zero tolerance for duplicate payments. What do you change?

    databasefailover
  • 56

    An Azure control-plane outage prevents deployments and secret rotation across 900 applications, although running workloads stay up; 99.95% customer contracts remain at risk, but you have six months and $2M, not enough to rewrite everything for a second cloud. What do you fund?

    secretsdeployment
  • 57

    A disaster-recovery exercise shows the second cloud can handle only 15% of the 4x seasonal peak for 240 services; the board demands multi-cloud resilience in 90 days, but the platform team has 12 engineers and no budget for dual-running every workload. How do you reset the commitment?

    multi-cloud
  • 58

    A $30M cloud migration is nine months late, has spent 70% of its budget, moved only 35% of 320 applications, and increased unit cloud cost by 22%; the board expects a recovery decision in two weeks and the data-center lease ends in 12 months. What do you recommend?

    migrationscloud-migration
  • 59

    A regulatory data-center exit is due in six months, but a planned 40-application wave exceeds delivery capacity by 18 applications and a lease extension carries a $1M penalty. How do you replan the portfolio?

    capacity
  • 60

    On a $30M modernization, the systems integrator reports 80% completion, but repository and production evidence shows 45%; only $3M and two quarters remain, and changing vendors would consume eight weeks. How do you choose between recovery and termination?

    procurementsystem-design
  • 61

    During a global SAP S/4HANA cutover for 28 countries, inventory reconciliation is off by 2.4% after four hours; stores open in six hours, the rollback point expires in 90 minutes, and order capture must remain available. Do you roll back?

    rollbackreact
  • 62

    Seven hours after ERP go-live, the bank interface has created duplicate payment instructions for 18,000 invoice obligations; rollback would discard 120,000 valid orders, statutory close is in 36 hours, and the bank can pause settlement for only two hours. What is your containment plan?

    rollbacktypes
  • 63

    A second ERP cutover is due in 45 days after stale mappings broke 17 of 300 interfaces; annual close cannot move, so how do you certify the interfaces before the retry?

    resiliencetypes
  • 64

    A security release changes a REST response used by 40 consumer teams at 12,000 requests per second; error rate jumps to 35%, rollback would reopen a critical vulnerability, and the API owner has no complete consumer list. What do you do in the first hour?

    restvulnerabilitiesrollback
  • 65

    A Kafka producer adds an enum value that breaks 40 consumers processing 8 million events per minute; lag reaches 90 minutes, and privacy rules prohibit replaying raw PII after 24 hours. How do you recover?

    piikafkaconcurrency
  • 66

    A vendor EOL forces an API contract shutdown in 60 days for 40 consumers, but Backstage lists only 28 owners and the old gateway cannot run past the deadline; customer traffic is 6,000 requests per second and dual-running is limited to 30 days. How do you migrate safely?

    procurementapigateway
  • 67

    An audit-agreed scope requires service-to-service encryption for 24 regulated services and their in-scope paths within 90 days; 80 teams exist, Istio adoption is 18%, and the platform team can support ten teams per month. What do you change without redefining the scope?

    encryptiondecision-making
  • 68

    Six architects have a backlog of 120 architecture reviews and a seven-week wait, delaying 30 product teams; regulators require independent review for high-risk changes, but headcount is frozen for two quarters. How do you unblock delivery?

    backlogarchitecture
  • 69

    A new enterprise encryption standard raises p99 latency by 45% for 30 edge products and breaches a 100 ms customer SLA; compliance is due in four months, and permanent waivers are prohibited. What hard decision do you make?

    encryptionlatency
  • 70

    A CASB alert finds 3 TB of customer data in an unapproved CRM with a public sharing link across 12 countries; breach notification may be due in 72 hours, but deleting the tenant would destroy evidence. What do you do?

    alerting
  • 71

    DLP detects 260 incidents where 4,000 employees pasted source code and customer text into public generative AI tools; support teams rely on those tools during a seasonal peak, and a total browser block would breach response SLAs. How do you contain the exposure?

    incidents
  • 72

    Discovery finds 900 OAuth grants across 140 unapproved SaaS tools, and a departed employee's token is still exporting payroll data; payroll closes in 24 hours, so revoking every grant at once would disrupt critical operations. What is your sequence?

    oauthtokenscloud
  • 73

    A middleware vendor announces EOL in 12 months for a platform used by 400 applications and 99.99% customer services; only $6M is funded, while a full rewrite is estimated at $18M and three years. What do you commit to?

    procurementestimationmiddleware
  • 74

    Your payroll SaaS provider enters insolvency while serving 70,000 employees in 18 countries; source escrow is six months stale, payday is in ten days, and local tax filings cannot be late. What is your first recovery decision?

    cloud-modelscloud
  • 75

    A proprietary database supporting 60 regulated medical applications reaches EOL in nine months; recertifying a replacement takes 12 months, vendor support cannot be extended, and unvalidated changes could halt product shipments. How do you handle the gap?

    procurementdatabasesoft-skills
  • 76

    A regulator gives 120 days to stop raw EU customer data from reaching the US, but 2 PB already feeds a global analytics product worth $40M annually; the product cannot be rebuilt before the deadline. What architecture decision do you make?

    estimationarchitecture
  • 77

    A new residency rule requires identity logs for six of 40 countries to remain local, while the SOC needs 90 days of global detection history; the deadline is 60 days and the current Entra tenant exports everything to one US SIEM. How do you resolve the conflict?

    estimation
  • 78

    A regulation requires customer-managed encryption keys in four months across 900 applications, but 35 legacy systems cannot integrate with a KMS and any outage over 20 minutes breaches public-service obligations. What do you commit to the regulator?

    encryptionsystem-design
  • 79

    Cloud spend rises from $3M to $6M per month in three weeks with no traffic growth; the CFO orders an immediate freeze, but the retail platform enters a 5x peak tomorrow and committed reservations cannot be canceled. What do you do today?

  • 80

    Across 220 Kubernetes clusters, idle capacity is 60% and annualized waste is $8M; an earlier rightsizing attempt caused 14 OOM incidents, while finance demands 25% savings in 90 days without reducing the 99.95% SLO. How do you proceed?

    kubernetesfinopscapacity
  • 81

    Cross-cloud replication for 5 billion events per day costs $900,000 monthly in egress; finance caps it at $400,000, the business requires a five-minute RPO, and EU raw events cannot leave the region. What do you change?

    replicationcloud-regions
  • 82

    A data mesh has 24 published data products, but nine miss freshness SLOs and seven have vacant owners; a regulatory report is due in 21 days and depends on five of the failing products. How do you recover ownership and delivery?

    ownershipslo
  • 83

    Orders and refunds domains publish conflicting customer-balance schemas across 80 million records, creating a $2M monthly reconciliation gap; both vice presidents reject the other's ownership, and quarter close is in 14 days with no time for a central warehouse rebuild. What do you decide?

    schemawarehousereact
  • 84

    A promotion service jumps from 2 million to 80 million Kafka events per minute, retry loops saturate 600 integrations, and duplicate payment requests appear; marketing refuses to cancel the live campaign, while accepted orders must not be lost. How do you contain the event storm?

    kafkaresilience
  • 85

    An SAP outage leaves 600 nightly files and EDI transfers queued, threatening emergency shipments in 22 countries; SAP recovery is four hours away, so how do you control the backlog?

    backlogdata-structures
  • 86

    An architecture repository imports a wrong dependency graph and an automated shutdown plan now targets 70 healthy consumers during an incident; what do you do?

    incidentsarchitecturedependencies
  • 87

    An $18M modernization delivered new services, but 72% of cases still follow the manual workflow and customer cycle time has not improved; the board reviews adoption in 90 days and no new funding is available. What do you change?

    decision-making
  • 88

    A $45M transformation promised 20% operating-cost reduction but costs are now 12% higher after 18 months; 110 applications have moved, cancellation threatens a regulatory milestone in six months, and the CFO will fund only one more quarter. What do you propose?

    milestonespromisesresilience
  • 89

    Forty of 220 applications are marked for retirement to save $5M annually, but discovery finds 600 undocumented Excel and robotic-process dependencies; license renewals are in 60 days and business owners will not accept a blackout. How do you retire them?

    dependenciesexcelconcurrency
  • 90

    A mainframe scheduled for retirement in 18 months still hosts three applications and seven years of legally retained records; vendor support ends in six months, archive extraction is only 92% complete, and auditors require records within four hours. What do you do?

    procurement
  • 91

    A critical CVE affects four forks of an ownerless shared Java authentication library used by 90 teams, and the exploit deadline is 30 days. How do you contain and repair it?

    estimationauth
  • 92

    Only 15% of 300 services use the approved event platform because its golden path cannot handle SAP messages or PII, so teams keep adding point-to-point links; integration incidents rose 35%, and leadership refuses a mandatory migration. What is your move?

    incidentsmigrationspii
  • 93

    The architecture exception register contains 180 waivers, 70 are expired, and 12 cover internet-facing systems with critical vulnerabilities; five architects can review only 20 per week, while an audit starts in 30 days and a blanket shutdown is not allowed. How do you burn down the debt?

    system-designvulnerabilitieserror-handling
  • 94

    After an acquisition, 160 of 430 architecture exceptions have no accountable owner and the audit evidence is due in 45 days; how do you make the inherited control position defensible?

    ownershiparchitectureerror-handling
  • 95

    The executive dashboard shows 92% architecture compliance across 700 applications, but teams game the denominator and a nonrepresentative spot check finds 28% policy failure; bonuses depend on the score and the board report is due in ten days. What do you report?

    architecture
  • 96

    The CEO wants a six-country launch in four weeks to secure a $25M contract, but threat modeling finds three critical controls missing across 45 services; delaying loses the contract, and the customer will accept only one production date. What do you recommend?

    threat-modeling
  • 97

    The CFO insists on an ERP go-live before annual close to avoid a $2M penalty, but the final rehearsal misses the two-hour recovery target by 70 minutes and 6 of 140 finance interfaces fail reconciliation; the date is in five days and no further full rehearsal fits. What is your go decision?

    reacttypes
  • 98

    An architect you mentor approved a synchronous chain of 14 services for a 6,000-transactions-per-second checkout, and it cascaded during Black Friday; the RCA is due in 48 hours, releases are frozen for seven days, and the architect is now excluded from incident meetings. What do you do?

    mentoringincidentstransactions
  • 99

    After a regional outage, the incident review finds 150 of 500 services cannot fail over although the roadmap funds new products for the next two quarters; a launch is due in eight weeks, only $5M can be redirected, and contractual RTO is 45 minutes. How do you correct the roadmap?

    roadmapincidentscloud-regions
  • 100

    After an incident, the CMDB is missing 220 of 900 applications and 30% of recovery ownership records are wrong; another seasonal peak starts in ten weeks, so how do you keep the inventory trustworthy?

    incidentsownership