DevOps interview questions: 23 questions and a scorecard for interviewers
The short answer
Good DevOps interview questions test how a candidate builds and runs CI/CD pipelines, manages infrastructure as code and containers, sets up monitoring and on-call, responds to incidents, controls cloud cost and security, and works with developers. Ask for real examples, such as a pipeline they built or the first fifteen minutes of an incident they handled, and listen for the steps they took and the part that was theirs. A recruiter screen before the client’s technical round should confirm the cloud and tooling stack, any certification the client asks for, the on-call rotation, work arrangement, right to work and start date. Score every candidate against the same five criteria so the decision rests on evidence.
All 23 questions with why you ask each one, what a strong answer shows and follow-ups, plus the devops engineer scorecard and rating guide. Free to download and adapt; no sign-up needed.
When to use these questions
DevOps engineers build and run the path from a developer’s commit to software running reliably in production: pipelines, infrastructure defined as code, containers, monitoring and the on-call response when something breaks. An interview needs to show how someone automates, how they reason when production misbehaves and how they work with the developers who depend on them, not only which tools appear on their resume. The strongest evidence comes from specific pipelines, incidents and changes, described step by step, with a clear line between their own work and the team’s.
For agency recruiters, the screen before the client’s technical round is where to confirm the essentials: recent production experience with the client’s cloud platform, infrastructure-as-code and CI/CD tools, the scale of the systems the candidate has run, any certification the client requires, and the practical facts of the on-call rotation, work arrangement, start date and pay expectations. Communication and ownership can be judged directly in the screen; leave hands-on technical assessment to the client’s engineers and pass on clear notes about what you heard.
23 DevOps interview questions
Grouped by what they test. Pick the questions that match the role, ask every candidate the same ones in the same order, and score each answer against the scorecard below.
CI/CD and releases
Ask about pipelines they built and releases they shipped. The detail they can give about each stage shows what they owned.
Question 1: Walk me through a CI/CD pipeline you built or maintain, from a developer’s commit to code running in production. Which stages did you add yourself?
- Why ask it:
- Tests whether they understand the whole delivery path, and separates their work from what they inherited.
- A strong answer shows:
- Clear stages such as build, automated tests, security checks, artifact storage, deployment and post-deploy checks, with their own additions named and the reason for each.
- Follow-up:
- Which stage fails most often, and what have you done about it?
Question 2: How do you roll out a risky change so that you can back it out quickly if something goes wrong?
- Why ask it:
- Shows how they limit the impact of a bad release.
- A strong answer shows:
- Techniques such as feature flags, canary or blue-green releases and automated rollback, chosen according to the risk, with a rollback they have actually tested.
Question 3: Developers say the pipeline takes forty minutes and they no longer trust the tests because some fail at random. What do you do?
- Why ask it:
- Tests whether they treat developer experience as part of the job.
- A strong answer shows:
- Measuring where the time goes, then caching, parallel jobs and quarantining flaky tests with an owner, agreed with developers rather than simply deleting tests.
Question 4: How do you make sure the version running in production is exactly the one that was tested?
- Why ask it:
- Checks their grasp of reproducible, traceable releases.
- A strong answer shows:
- Building an artifact once, versioning it and promoting that same artifact through each environment, with a record of what was deployed where and when.
Question 5: How do you handle secrets, such as API keys and database passwords, in pipelines and deployments?
- Why ask it:
- A secret leaked through a pipeline or repository can expose the whole environment.
- A strong answer shows:
- A secrets manager or vault, nothing stored in repositories or printed in logs, narrowly scoped credentials and regular rotation, with short-lived tokens where the platform allows.
Infrastructure as code and containers
These questions show whether infrastructure is managed as carefully as application code, and how deep their container experience goes.
Question 6: In your current or last environment, which parts of the infrastructure were defined as code and which were still set up by hand? Why?
- Why ask it:
- Gives an honest picture of their real environment rather than an ideal one.
- A strong answer shows:
- A candid inventory, the tools used, such as Terraform, CloudFormation, Pulumi or Ansible, and sensible reasons for anything still manual, with a plan to change it.
Question 7: Someone changed a setting directly in the cloud console, and now the live environment no longer matches your infrastructure code. How do you find drift like that, and what do you do about it?
- Why ask it:
- Tests discipline around a common, real-world problem.
- A strong answer shows:
- Regular plan or diff runs to detect drift, bringing the change back through code review, limiting who can change things by hand, and talking to the person rather than blaming them.
Question 8: How do you structure infrastructure code so that several teams and environments can reuse it safely?
- Why ask it:
- Shows whether their infrastructure code works beyond a single person or project.
- A strong answer shows:
- Versioned, reusable modules, separate settings for each environment, shared state with locking, and code review for every infrastructure change.
Question 9: Explain to me, as someone who isn’t an engineer, why a team would package its applications in containers and what an orchestrator such as Kubernetes adds.
- Why ask it:
- Tests understanding and communication at the same time, and a recruiter can judge it directly.
- A strong answer shows:
- Plain language about consistent packaging, automatic restarts, scaling and rolling updates, and an honest note on when it adds more complexity than it is worth.
Question 10: Tell me about a container or Kubernetes problem you tracked down, such as a service that kept restarting or couldn’t reach another service.
- Why ask it:
- Shows hands-on depth behind the tool names on a resume.
- A strong answer shows:
- A methodical path through events, logs, resource limits, health checks, configuration and networking, ending in a root cause and a fix.
- Follow-up:
- What did you add so the next person could diagnose it faster?
Monitoring, on-call and incidents
Ask how they know something is wrong, what they do when it is, and how the team learns from it.
Question 11: How do you decide what deserves an alert that wakes someone up, and what can wait until the morning?
- Why ask it:
- Tests judgment about alert quality and the health of the on-call team.
- A strong answer shows:
- Paging only on symptoms users would notice, such as errors and slow responses, tied to clear thresholds or service-level objectives, with an owner and a runbook for each alert.
Question 12: Describe the last on-call rotation you were part of. How often were you paged, and what did the team do to reduce unnecessary pages?
- Why ask it:
- Gives a realistic view of their on-call experience and attitude.
- A strong answer shows:
- A concrete description of the rotation and handovers, and specific actions such as fixing root causes, tuning thresholds or deleting alerts nobody acted on.
Question 13: Walk me through a production incident where you were one of the first responders. What did you do in the first fifteen minutes?
- Why ask it:
- Shows how they behave under pressure while the cause is still unknown.
- A strong answer shows:
- Assessing user impact, raising the incident and agreeing roles, restoring service first through a rollback or failover, and keeping a timeline and regular updates.
- Follow-up:
- Who did you keep informed, and how often?
Question 14: What makes a postmortem useful rather than a document nobody reads?
- Why ask it:
- Tests whether incidents lead to lasting improvements.
- A strong answer shows:
- A blameless review with a clear timeline, contributing factors rather than one person at fault, and actions with owners and dates that are tracked to completion.
Cloud cost, security and working with developers
DevOps engineers spend the company’s money and hold powerful access. Look for care with both, and for a habit of making developers more independent.
Question 15: The cloud bill jumped last month and finance wants to know why. How do you investigate?
- Why ask it:
- Tests cost awareness and a methodical investigation.
- A strong answer shows:
- Breaking costs down by service, account and tag, finding the change behind the jump, fixing it, and adding budgets, alerts or tagging rules so it is caught sooner next time.
Question 16: How do you limit what pipelines, servers and engineers can access in your cloud accounts?
- Why ask it:
- Checks least-privilege habits where mistakes are costly.
- A strong answer shows:
- Narrow roles for each workload and person, separate accounts or projects for production, short-lived credentials, audit logging and regular access reviews.
Question 17: How do you keep container images and third-party dependencies free of known vulnerabilities without blocking every release?
- Why ask it:
- Shows how they balance security with delivery speed.
- A strong answer shows:
- Automated scanning in the pipeline, small base images, rules based on severity and exposure, regular patching, and time-limited exceptions with an owner.
Question 18: Tell me about a time a development team pushed back on a change you wanted, such as a new deployment process or stricter checks. How did you bring them along?
- Why ask it:
- Tests influence and collaboration, which decide whether DevOps changes stick.
- A strong answer shows:
- Listening to their concerns, piloting with one team, showing the benefit with evidence, and making the safer way the easiest way, for example through templates or self-service tools.
Must-haves and logistics
Ask these of every candidate before the client’s technical round, and check the answers against the resume.
Question 19: Which cloud platforms, infrastructure-as-code tools, CI/CD systems and container platforms have you used in production in the last two years, and for systems of what size?
- Why ask it:
- Confirms hands-on experience with the client’s stack and scale.
- A strong answer shows:
- Specific tools tied to recent roles and real workloads, with honesty about anything used only in labs or side projects.
Question 20: Do you hold any certifications the client has asked for, such as AWS Certified DevOps Engineer – Professional, Microsoft Certified: DevOps Engineer Expert or the Certified Kubernetes Administrator (CKA)?
- Why ask it:
- Some clients list a cloud or Kubernetes certification as a requirement.
- A strong answer shows:
- The exact certification and date earned, and a badge link, transcript link or certification ID the client can verify with the issuer.
Question 21: The role is [remote, hybrid or on-site, and location] with [the on-call rotation, such as one week in six]. Have you worked a similar rotation, does the arrangement suit you, and when could you start?
- Why ask it:
- Rules out on-call and work arrangement mismatches before the client invests interview time.
- A strong answer shows:
- A clear yes, or the specific constraint, relevant on-call experience and a firm start date or notice period.
Question 22: Are you legally authorized to work in [country] for this employer, and will you need visa sponsorship now or in the future?
- Why ask it:
- Confirms eligibility; ask every candidate the same question in the same way.
- A strong answer shows:
- A direct answer, recorded the same way for every candidate.
Question 23: What pay range are you looking for in this role?
- Why ask it:
- Checks fit with the client’s budget without asking about pay history.
- A strong answer shows:
- A realistic range you can compare with the client’s budget.
DevOps engineer interview scorecard
Five criteria for this role, with what a score of 1, 3 and 5 looks like. Scores of 2 and 4 sit between them.
| Criterion | What it means | Score 1 looks like | Score 3 looks like | Score 5 looks like |
|---|---|---|---|---|
| Automation and delivery | Builds pipelines and processes that ship changes safely and repeatably. | Describes manual steps, or cannot explain what their pipeline does. | Explains a pipeline they work on clearly, including how a bad release is rolled back. | Has designed pipelines end to end, with safe rollout strategies, traceable artifacts and fast feedback for developers. |
| Infrastructure and platform depth | Manages infrastructure as code and container platforms at the level the role needs. | Names tools but cannot describe a real problem solved with them. | Manages infrastructure through code and gives a clear troubleshooting example. | Designs reusable infrastructure code, handles drift and diagnoses platform problems methodically. |
| Reliability and incident response | Builds useful monitoring, stays effective on call and learns from incidents. | No clear incident example, or accepts constant alert noise as normal. | Responds calmly to incidents and contributes to blameless reviews. | Leads incidents, designs alerting around user impact and drives postmortem actions to completion. |
| Security and cost awareness | Protects access and secrets and spends cloud money with care. | Handles secrets loosely, or treats broad access and cloud spend as someone else’s problem. | Applies least privilege and secrets management, and has investigated a cost problem. | Builds security and cost controls into the platform so the safe, efficient option is the default. |
| Collaboration and enablement | Works well with developers and helps them deliver independently. | Describes developers as the problem, or acts as a gatekeeper. | Works constructively with developers and explains technical work plainly. | Wins teams over to better practices and builds self-service tools that reduce dependence on the DevOps team. |
The 1–5 rating scale
The same scale for every criterion and every candidate.
| Score | Level | What it means |
|---|---|---|
| 1 | Well below requirement | No relevant evidence, or an answer that contradicts the requirement. |
| 2 | Below requirement | Partial evidence with important gaps. |
| 3 | Meets requirement | Clear, relevant evidence at the level the role needs. |
| 4 | Above requirement | Strong, specific evidence beyond the expected level. |
| 5 | Exceptional | Repeated high-quality evidence with clear impact. |
How to run the interview with these devops interview questions
- 01
Step 01
Agree the must-haves first
Confirm the essential credentials, experience and availability with the hiring manager or client before any interviews. - 02
Step 02
Pick 8 to 12 questions
Take the must-have questions, then the questions that test what this role needs most. Use the same set, in the same order, for every candidate. - 03
Step 03
Ask for real examples
When you hear “we” or “I would”, ask what the candidate personally did, and what happened in the end. - 04
Step 04
Score before you discuss
Rate each criterion on the scorecard with the evidence behind it, then compare with other interviewers. - 05
Step 05
Verify before you submit
Check licenses, certifications and right to work against the original source before you put the candidate forward.
Red flags, and questions not to ask
- Lists Kubernetes, Terraform and several clouds but cannot describe a real problem they solved with any of them.
- Describes keeping secrets in code, chat or shared documents, or giving everyone full production access, as normal.
- Treats constant, ignored alerts as part of the job and has never tried to reduce them.
- Blames developers or other teams for every outage, with no example of a blameless review.
- Says “we” throughout and cannot say which parts of a pipeline or platform they built themselves.
- Age, marital or family status, pregnancy or plans for children, religion, ethnicity or national origin, sexual orientation or gender identity. These are protected characteristics under the UK Equality Act 2010 and US federal law, and they say nothing about whether someone can do the job.
- Health, sickness absence or disability before an offer. You can ask whether the candidate needs any adjustments for the interview, and whether they can do the essential tasks of the job.
Screen DevOps engineer applicants before the first call
Add these questions to a Beatview AI interview and every applicant answers them on video or audio, with the same time limit. Beatview scores each answer against your criteria and shows the reasoning, and you can share the shortlist with your client through a password-protected link. AI interviews are on the Pro plan; the Free plan screens resumes for one active job.
DevOps interview questions: frequently asked questions
Still deciding?
Bring a live vacancy and we’ll walk through where automation ends and recruiter review begins.
Ask for real examples that test CI/CD, infrastructure as code, containers, monitoring and on-call, incident response, cloud cost and security, and how they work with developers, such as a pipeline they built or the first fifteen minutes of an incident they handled. Add must-have questions on the client’s cloud and tooling stack, any required certification, the on-call rotation, work arrangement, right to work and start date, and ask every candidate the same questions in the same order.
It depends on the client’s platform, and recent hands-on experience usually matters more. Clients on AWS may ask for AWS Certified DevOps Engineer – Professional; clients on Azure may ask for Microsoft Certified: DevOps Engineer Expert, which requires the AZ-400 exam and an Azure Administrator Associate or Azure Developer Associate certification; and teams that run Kubernetes may ask for the Linux Foundation’s Certified Kubernetes Administrator (CKA), a performance-based exam solved from a command line. To verify, ask for the AWS digital badge link, a share link to the candidate’s Microsoft Learn transcript, or the CKA certification ID to check with their last name on the Linux Foundation’s verification page.
Agree it with the client in advance and keep it short and realistic, such as reviewing a pipeline configuration, fixing a broken deployment in a sandbox or talking through a response to a sample alert. Give every candidate the same task, time limit, information and scoring guide, let them use the documentation they would use at work, and ask them to explain their reasoning, which shows more than the finished result. Never use the exercise to get real work done for free, and make adjustments if a candidate asks for them.
Job titles overlap and vary between companies, so start from the client’s job description rather than the title. Keep the core questions and shift the weight: for a site reliability role, spend more time on monitoring, service-level objectives and incidents; for a platform role, on infrastructure code, internal tooling and making developers self-sufficient; for a DevOps role, on pipelines and releases.
Get the devops interview questions template
All 23 questions with why you ask each one, what a strong answer shows and follow-ups, plus the devops engineer scorecard and rating guide.
Opens in Excel, Google Sheets or Numbers. Version 2 October 2026.
Sources: AWS: AWS Certified DevOps Engineer – Professional; AWS: Certification FAQs, including how to verify a certification; Microsoft Learn: Microsoft Certified: DevOps Engineer Expert; Microsoft Learn: View and share your transcript; Linux Foundation: Certified Kubernetes Administrator (CKA); Linux Foundation: Verify a certification. This template is general guidance, not legal advice.