A feature lets users give a URL and your backend fetches it to build a link preview. What can go wrong?

Answer it out loud before you open anything. The value of the flags below is in comparing them to what you actually said.

The situation behind the question

The service runs in a cloud VPC alongside internal admin services and has an instance metadata endpoint available on the standard link-local address.

What it is really testing

Whether the candidate recognises server-side request forgery from the description and understands why the naive defences do not hold. The cloud detail in the scenario is the point: the backend can reach things the internet cannot.

Where the mechanism is taught