Supply Chain
How do you know the artifact running in production is the one you built?
Whether the candidate can reason about the path from dependency to running process as attack surface, and about what a scanner finding actually means.
The situation behind the question
A pipeline builds images tagged
service:latest and the deployment references that tag. The registry allows pushes from three service accounts and four humans. Nothing verifies who built an image, and the vulnerability scanner reports 340 findings, all of which have been acknowledged.