Skip to content
    Free template · Updated 2 October 2026

    DevOps interview questions: 23 questions and a scorecard for interviewers

    The short answer

    Good DevOps interview questions test how a candidate builds and runs CI/CD pipelines, manages infrastructure as code and containers, sets up monitoring and on-call, responds to incidents, controls cloud cost and security, and works with developers. Ask for real examples, such as a pipeline they built or the first fifteen minutes of an incident they handled, and listen for the steps they took and the part that was theirs. A recruiter screen before the client’s technical round should confirm the cloud and tooling stack, any certification the client asks for, the on-call rotation, work arrangement, right to work and start date. Score every candidate against the same five criteria so the decision rests on evidence.

    All 23 questions with why you ask each one, what a strong answer shows and follow-ups, plus the devops engineer scorecard and rating guide. Free to download and adapt; no sign-up needed.

    When to use it

    When to use these questions

    DevOps engineers build and run the path from a developer’s commit to software running reliably in production: pipelines, infrastructure defined as code, containers, monitoring and the on-call response when something breaks. An interview needs to show how someone automates, how they reason when production misbehaves and how they work with the developers who depend on them, not only which tools appear on their resume. The strongest evidence comes from specific pipelines, incidents and changes, described step by step, with a clear line between their own work and the team’s.

    For agency recruiters, the screen before the client’s technical round is where to confirm the essentials: recent production experience with the client’s cloud platform, infrastructure-as-code and CI/CD tools, the scale of the systems the candidate has run, any certification the client requires, and the practical facts of the on-call rotation, work arrangement, start date and pay expectations. Communication and ownership can be judged directly in the screen; leave hands-on technical assessment to the client’s engineers and pass on clear notes about what you heard.

    23 questions

    23 DevOps interview questions

    Grouped by what they test. Pick the questions that match the role, ask every candidate the same ones in the same order, and score each answer against the scorecard below.

    CI/CD and releases

    Ask about pipelines they built and releases they shipped. The detail they can give about each stage shows what they owned.

    1. Question 1: Walk me through a CI/CD pipeline you built or maintain, from a developer’s commit to code running in production. Which stages did you add yourself?

      Why ask it:
      Tests whether they understand the whole delivery path, and separates their work from what they inherited.
      A strong answer shows:
      Clear stages such as build, automated tests, security checks, artifact storage, deployment and post-deploy checks, with their own additions named and the reason for each.
      Follow-up:
      Which stage fails most often, and what have you done about it?
    2. Question 2: How do you roll out a risky change so that you can back it out quickly if something goes wrong?

      Why ask it:
      Shows how they limit the impact of a bad release.
      A strong answer shows:
      Techniques such as feature flags, canary or blue-green releases and automated rollback, chosen according to the risk, with a rollback they have actually tested.
    3. Question 3: Developers say the pipeline takes forty minutes and they no longer trust the tests because some fail at random. What do you do?

      Why ask it:
      Tests whether they treat developer experience as part of the job.
      A strong answer shows:
      Measuring where the time goes, then caching, parallel jobs and quarantining flaky tests with an owner, agreed with developers rather than simply deleting tests.
    4. Question 4: How do you make sure the version running in production is exactly the one that was tested?

      Why ask it:
      Checks their grasp of reproducible, traceable releases.
      A strong answer shows:
      Building an artifact once, versioning it and promoting that same artifact through each environment, with a record of what was deployed where and when.
    5. Question 5: How do you handle secrets, such as API keys and database passwords, in pipelines and deployments?

      Why ask it:
      A secret leaked through a pipeline or repository can expose the whole environment.
      A strong answer shows:
      A secrets manager or vault, nothing stored in repositories or printed in logs, narrowly scoped credentials and regular rotation, with short-lived tokens where the platform allows.

    Infrastructure as code and containers

    These questions show whether infrastructure is managed as carefully as application code, and how deep their container experience goes.

    1. Question 6: In your current or last environment, which parts of the infrastructure were defined as code and which were still set up by hand? Why?

      Why ask it:
      Gives an honest picture of their real environment rather than an ideal one.
      A strong answer shows:
      A candid inventory, the tools used, such as Terraform, CloudFormation, Pulumi or Ansible, and sensible reasons for anything still manual, with a plan to change it.
    2. Question 7: Someone changed a setting directly in the cloud console, and now the live environment no longer matches your infrastructure code. How do you find drift like that, and what do you do about it?

      Why ask it:
      Tests discipline around a common, real-world problem.
      A strong answer shows:
      Regular plan or diff runs to detect drift, bringing the change back through code review, limiting who can change things by hand, and talking to the person rather than blaming them.
    3. Question 8: How do you structure infrastructure code so that several teams and environments can reuse it safely?

      Why ask it:
      Shows whether their infrastructure code works beyond a single person or project.
      A strong answer shows:
      Versioned, reusable modules, separate settings for each environment, shared state with locking, and code review for every infrastructure change.
    4. Question 9: Explain to me, as someone who isn’t an engineer, why a team would package its applications in containers and what an orchestrator such as Kubernetes adds.

      Why ask it:
      Tests understanding and communication at the same time, and a recruiter can judge it directly.
      A strong answer shows:
      Plain language about consistent packaging, automatic restarts, scaling and rolling updates, and an honest note on when it adds more complexity than it is worth.
    5. Question 10: Tell me about a container or Kubernetes problem you tracked down, such as a service that kept restarting or couldn’t reach another service.

      Why ask it:
      Shows hands-on depth behind the tool names on a resume.
      A strong answer shows:
      A methodical path through events, logs, resource limits, health checks, configuration and networking, ending in a root cause and a fix.
      Follow-up:
      What did you add so the next person could diagnose it faster?

    Monitoring, on-call and incidents

    Ask how they know something is wrong, what they do when it is, and how the team learns from it.

    1. Question 11: How do you decide what deserves an alert that wakes someone up, and what can wait until the morning?

      Why ask it:
      Tests judgment about alert quality and the health of the on-call team.
      A strong answer shows:
      Paging only on symptoms users would notice, such as errors and slow responses, tied to clear thresholds or service-level objectives, with an owner and a runbook for each alert.
    2. Question 12: Describe the last on-call rotation you were part of. How often were you paged, and what did the team do to reduce unnecessary pages?

      Why ask it:
      Gives a realistic view of their on-call experience and attitude.
      A strong answer shows:
      A concrete description of the rotation and handovers, and specific actions such as fixing root causes, tuning thresholds or deleting alerts nobody acted on.
    3. Question 13: Walk me through a production incident where you were one of the first responders. What did you do in the first fifteen minutes?

      Why ask it:
      Shows how they behave under pressure while the cause is still unknown.
      A strong answer shows:
      Assessing user impact, raising the incident and agreeing roles, restoring service first through a rollback or failover, and keeping a timeline and regular updates.
      Follow-up:
      Who did you keep informed, and how often?
    4. Question 14: What makes a postmortem useful rather than a document nobody reads?

      Why ask it:
      Tests whether incidents lead to lasting improvements.
      A strong answer shows:
      A blameless review with a clear timeline, contributing factors rather than one person at fault, and actions with owners and dates that are tracked to completion.

    Cloud cost, security and working with developers

    DevOps engineers spend the company’s money and hold powerful access. Look for care with both, and for a habit of making developers more independent.

    1. Question 15: The cloud bill jumped last month and finance wants to know why. How do you investigate?

      Why ask it:
      Tests cost awareness and a methodical investigation.
      A strong answer shows:
      Breaking costs down by service, account and tag, finding the change behind the jump, fixing it, and adding budgets, alerts or tagging rules so it is caught sooner next time.
    2. Question 16: How do you limit what pipelines, servers and engineers can access in your cloud accounts?

      Why ask it:
      Checks least-privilege habits where mistakes are costly.
      A strong answer shows:
      Narrow roles for each workload and person, separate accounts or projects for production, short-lived credentials, audit logging and regular access reviews.
    3. Question 17: How do you keep container images and third-party dependencies free of known vulnerabilities without blocking every release?

      Why ask it:
      Shows how they balance security with delivery speed.
      A strong answer shows:
      Automated scanning in the pipeline, small base images, rules based on severity and exposure, regular patching, and time-limited exceptions with an owner.
    4. Question 18: Tell me about a time a development team pushed back on a change you wanted, such as a new deployment process or stricter checks. How did you bring them along?

      Why ask it:
      Tests influence and collaboration, which decide whether DevOps changes stick.
      A strong answer shows:
      Listening to their concerns, piloting with one team, showing the benefit with evidence, and making the safer way the easiest way, for example through templates or self-service tools.

    Must-haves and logistics

    Ask these of every candidate before the client’s technical round, and check the answers against the resume.

    1. Question 19: Which cloud platforms, infrastructure-as-code tools, CI/CD systems and container platforms have you used in production in the last two years, and for systems of what size?

      Why ask it:
      Confirms hands-on experience with the client’s stack and scale.
      A strong answer shows:
      Specific tools tied to recent roles and real workloads, with honesty about anything used only in labs or side projects.
    2. Question 20: Do you hold any certifications the client has asked for, such as AWS Certified DevOps Engineer – Professional, Microsoft Certified: DevOps Engineer Expert or the Certified Kubernetes Administrator (CKA)?

      Why ask it:
      Some clients list a cloud or Kubernetes certification as a requirement.
      A strong answer shows:
      The exact certification and date earned, and a badge link, transcript link or certification ID the client can verify with the issuer.
    3. Question 21: The role is [remote, hybrid or on-site, and location] with [the on-call rotation, such as one week in six]. Have you worked a similar rotation, does the arrangement suit you, and when could you start?

      Why ask it:
      Rules out on-call and work arrangement mismatches before the client invests interview time.
      A strong answer shows:
      A clear yes, or the specific constraint, relevant on-call experience and a firm start date or notice period.
    4. Question 22: Are you legally authorized to work in [country] for this employer, and will you need visa sponsorship now or in the future?

      Why ask it:
      Confirms eligibility; ask every candidate the same question in the same way.
      A strong answer shows:
      A direct answer, recorded the same way for every candidate.
    5. Question 23: What pay range are you looking for in this role?

      Why ask it:
      Checks fit with the client’s budget without asking about pay history.
      A strong answer shows:
      A realistic range you can compare with the client’s budget.
    Example rubric

    DevOps engineer interview scorecard

    Five criteria for this role, with what a score of 1, 3 and 5 looks like. Scores of 2 and 4 sit between them.

    DevOps engineer interview scorecard
    CriterionWhat it meansScore 1 looks likeScore 3 looks likeScore 5 looks like
    Automation and deliveryBuilds pipelines and processes that ship changes safely and repeatably.Describes manual steps, or cannot explain what their pipeline does.Explains a pipeline they work on clearly, including how a bad release is rolled back.Has designed pipelines end to end, with safe rollout strategies, traceable artifacts and fast feedback for developers.
    Infrastructure and platform depthManages infrastructure as code and container platforms at the level the role needs.Names tools but cannot describe a real problem solved with them.Manages infrastructure through code and gives a clear troubleshooting example.Designs reusable infrastructure code, handles drift and diagnoses platform problems methodically.
    Reliability and incident responseBuilds useful monitoring, stays effective on call and learns from incidents.No clear incident example, or accepts constant alert noise as normal.Responds calmly to incidents and contributes to blameless reviews.Leads incidents, designs alerting around user impact and drives postmortem actions to completion.
    Security and cost awarenessProtects access and secrets and spends cloud money with care.Handles secrets loosely, or treats broad access and cloud spend as someone else’s problem.Applies least privilege and secrets management, and has investigated a cost problem.Builds security and cost controls into the platform so the safe, efficient option is the default.
    Collaboration and enablementWorks well with developers and helps them deliver independently.Describes developers as the problem, or acts as a gatekeeper.Works constructively with developers and explains technical work plainly.Wins teams over to better practices and builds self-service tools that reduce dependence on the DevOps team.
    Scoring

    The 1–5 rating scale

    The same scale for every criterion and every candidate.

    The 1–5 rating scale
    ScoreLevelWhat it means
    1Well below requirementNo relevant evidence, or an answer that contradicts the requirement.
    2Below requirementPartial evidence with important gaps.
    3Meets requirementClear, relevant evidence at the level the role needs.
    4Above requirementStrong, specific evidence beyond the expected level.
    5ExceptionalRepeated high-quality evidence with clear impact.
    How to use it

    How to run the interview with these devops interview questions

    1. 01

      Step 01

      Agree the must-haves first

      Confirm the essential credentials, experience and availability with the hiring manager or client before any interviews.
    2. 02

      Step 02

      Pick 8 to 12 questions

      Take the must-have questions, then the questions that test what this role needs most. Use the same set, in the same order, for every candidate.
    3. 03

      Step 03

      Ask for real examples

      When you hear “we” or “I would”, ask what the candidate personally did, and what happened in the end.
    4. 04

      Step 04

      Score before you discuss

      Rate each criterion on the scorecard with the evidence behind it, then compare with other interviewers.
    5. 05

      Step 05

      Verify before you submit

      Check licenses, certifications and right to work against the original source before you put the candidate forward.
    Watch out

    Red flags, and questions not to ask

    • Lists Kubernetes, Terraform and several clouds but cannot describe a real problem they solved with any of them.
    • Describes keeping secrets in code, chat or shared documents, or giving everyone full production access, as normal.
    • Treats constant, ignored alerts as part of the job and has never tried to reduce them.
    • Blames developers or other teams for every outage, with no example of a blameless review.
    • Says “we” throughout and cannot say which parts of a pipeline or platform they built themselves.
    • Age, marital or family status, pregnancy or plans for children, religion, ethnicity or national origin, sexual orientation or gender identity. These are protected characteristics under the UK Equality Act 2010 and US federal law, and they say nothing about whether someone can do the job.
    • Health, sickness absence or disability before an offer. You can ask whether the candidate needs any adjustments for the interview, and whether they can do the essential tasks of the job.
    Run it in Beatview

    Screen DevOps engineer applicants before the first call

    Add these questions to a Beatview AI interview and every applicant answers them on video or audio, with the same time limit. Beatview scores each answer against your criteria and shows the reasoning, and you can share the shortlist with your client through a password-protected link. AI interviews are on the Pro plan; the Free plan screens resumes for one active job.

    FAQ

    DevOps interview questions: frequently asked questions

    Still deciding?

    Bring a live vacancy and we’ll walk through where automation ends and recruiter review begins.

    Ask for real examples that test CI/CD, infrastructure as code, containers, monitoring and on-call, incident response, cloud cost and security, and how they work with developers, such as a pipeline they built or the first fifteen minutes of an incident they handled. Add must-have questions on the client’s cloud and tooling stack, any required certification, the on-call rotation, work arrangement, right to work and start date, and ask every candidate the same questions in the same order.

    It depends on the client’s platform, and recent hands-on experience usually matters more. Clients on AWS may ask for AWS Certified DevOps Engineer – Professional; clients on Azure may ask for Microsoft Certified: DevOps Engineer Expert, which requires the AZ-400 exam and an Azure Administrator Associate or Azure Developer Associate certification; and teams that run Kubernetes may ask for the Linux Foundation’s Certified Kubernetes Administrator (CKA), a performance-based exam solved from a command line. To verify, ask for the AWS digital badge link, a share link to the candidate’s Microsoft Learn transcript, or the CKA certification ID to check with their last name on the Linux Foundation’s verification page.

    Agree it with the client in advance and keep it short and realistic, such as reviewing a pipeline configuration, fixing a broken deployment in a sandbox or talking through a response to a sample alert. Give every candidate the same task, time limit, information and scoring guide, let them use the documentation they would use at work, and ask them to explain their reasoning, which shows more than the finished result. Never use the exercise to get real work done for free, and make adjustments if a candidate asks for them.

    Job titles overlap and vary between companies, so start from the client’s job description rather than the title. Keep the core questions and shift the weight: for a site reliability role, spend more time on monitoring, service-level objectives and incidents; for a platform role, on infrastructure code, internal tooling and making developers self-sufficient; for a DevOps role, on pipelines and releases.

    Download

    Get the devops interview questions template

    All 23 questions with why you ask each one, what a strong answer shows and follow-ups, plus the devops engineer scorecard and rating guide.

    Opens in Excel, Google Sheets or Numbers. Version 2 October 2026.

    Download the free template (CSV)
    Start free

    Put the template to work on a live role.

    Beatview screens every application against your criteria and interviews the shortlist with the same structured questions. The Free plan covers one active job; AI interviews are on Pro.

    • Free plan with one active role
    • Runs alongside your ATS
    • Recruiters keep every decision

    Page last reviewed by the Beatview team.