47. Interview Questions Asked in MNC Interviews
47.6 Cloud and AWS Security MNC Themes
S3, IAM, SG, CloudTrail – Maharashtra SME examples. Aata pudhe.
Q45. What AWS mistakes do interviewers expect you to catch?
Frequently asked across MNC cloud-security rounds (candidate-reported). Public S3 without Block Public Access, IAM users with unused access keys, security groups open 0.0.0.0/0 on 22/3389/3306, long-lived keys in code, and missing CloudTrail/GuardDuty. I use Sahyadri Free Tier labs to practise fixes.
Q46. Explain least privilege for IAM.
(Theme: TechGig / Wipro PoLP — candidate-reported; cloud application frequent across MNCs.) Grant only the actions and resources needed for a task. Prefer roles on EC2 over embedded access keys. Review unused privileges. For Amir the developer I avoid AdministratorAccess "just for speed".
Q47. How do you respond if AWS keys were committed to a public repo?
Frequently asked scenario across MNC interviews (candidate-reported). Deactivate keys immediately, rotate secrets, review CloudTrail for API use, scrub git history per process, move the app to an instance role, and add secret scanning. Same day – not "tomorrow".
Q48. Security group versus NACLs – interview short form?
Frequently asked (candidate-reported). Security groups are stateful allow-rules on ENIs; NACLs are subnet-level and stateless. Most day-to-day EC2 exposure mistakes I see in labs are SG 0.0.0.0/0 rules.
Q49. Why enable CloudTrail and GuardDuty in a talking-point answer?
Frequently asked (candidate-reported). CloudTrail records control-plane API activity for investigation. GuardDuty adds managed threat findings. Together they support detect and respond for an AWS account used by Raja-Rani’s lab.
Q50. S3 public website versus accidental public bucket?
Frequently asked (candidate-reported). Deliberate static hosting is a design choice with review. Accidental public listing of private objects is a breach pattern. Default to Block Public Access patterns; use CloudFront when public read is required.
Q51. How does encryption protect data at rest?
(Theme: TechGig / Wipro — candidate-reported.) Encryption turns data into ciphertext without the key. If a disk or snapshot is stolen, plaintext is not trivial to read. I still manage keys carefully (KMS ideas), because encryption without key hygiene fails open to the key holder.
Q52. Zero-day – what do you say in an MNC round?
(Theme: TechGig / Wipro — candidate-reported.) A zero-day is a vulnerability without a public patch at discovery/exploit time. Mitigation mindset: defence-in-depth, least privilege, IDS/EDR behavioural detection, rapid patch when vendor fix lands, and network exposure reduction. No fake claims that I "found zero-days for clients".
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Finds public S3 / open SG / leaked keys | BPA; SG least privilege; secret scan; CloudTrail + GuardDuty; rotate keys |
| Abuses over-privileged IAM | Permission boundaries; access advisor reviews; MFA |
Ravindra Bagale's Tip
In the cloud round, students say "I know all 200 AWS services". The interviewer asks for misconfig stories. Three: public S3, open port 22, a leaked key – plus the fix. This wins. Got it?
Ravindra Bagale's Tip – मराठी
Cloud round मध्ये students "I know all 200 AWS services" म्हणतात. Interviewer misconfig stories विचारतो. तीन: public S3, open 22, leaked key – plus fix. हे जिंकते. समजले का?
Ravindra Bagale's Tip – हिंदी
Cloud round में students कहते हैं "I know all 200 AWS services". Interviewer misconfig stories पूछता है. तीन: public S3, open 22, leaked key – plus fix. यही जिताता है. समझ आया?
Lab
On OWN Free Tier only: enable Block Public Access on a practice bucket, create a bad SG rule on a throwaway instance then remove it, and screenshot CloudTrail event history for a CreateBucket or SG change. Portfolio folder mnc-cloud.