Pick a focused question that fits your time, stack, and interview goal.
How much time do you have?
Show one-drill sessions you can finish now.
1225 drills fit a 20-minute session. Closest fits first.
Page 1 of 52
Explain API behavior when data and operations cross services with separate data ownership.
Designs an async export flow for large reports without blocking API requests or exhausting database and memory resources.
Designs dashboard APIs with precomputed metrics, freshness rules, query cost control, and drill-down support.
Combines restrained autonomy, curated tools, durable state, approval, memory, recovery, MCP trust, evaluation, and operational controls.
Designs tenant isolation across API, data, cache, background jobs, search, and admin access.
Connects product success, layered evals, calibrated graders, release gates, guarded rollout, traces, monitoring, feedback, and incident learning.
Designs a checkout or order creation flow that survives client retries without duplicate orders, payments, or messages.
Combines governed ingestion, authorized hybrid retrieval, reranking, grounded generation, citations, evaluation, observability, and fallback.
Designs an external partner API with authentication, versioning, rate limits, idempotency, documentation, and compatibility.
Designs synchronization with an external system using cursors, retries, idempotency, rate limits, and reconciliation.
Designs a multi-service business workflow using local transactions, durable progress, idempotency, retries, and domain-specific compensation.
Designs a file workflow with metadata, durable storage, validation, access control, scanning, and safe downloads.
Combines threat modeling, injection containment, data minimization, tenant isolation, tools, audit, incident response, and governance.
Designs authenticated, replay-resistant webhook intake with durable acknowledgement, idempotent asynchronous processing, ordering policy, and reconciliation.
Designs a safe admin import flow with upload staging, validation, preview, confirmation, idempotency, and rollback strategy.
Designs a sharding strategy with a stable key, balanced load, routing, resharding, cross-shard limits, and operational ownership.
Designs user reports, moderation queues, actions, audit history, abuse controls, and appeal-friendly decisions.
Designs layered public API protection with caller identity, quotas, burst limits, abuse signals, and client-friendly responses.
Designs authorization that combines roles, permissions, tenant context, resource ownership, and auditability.
Designs live updates with polling, server-sent events, or WebSockets while preserving authorization, ordering, scale, and fallback behavior.
Designs plan entitlements, provider webhooks, idempotent billing updates, access checks, grace periods, and support overrides.
Designs a controlled support impersonation workflow with scoped access, approvals, visible banners, audit trails, and session boundaries.
Combines explicit trust boundaries, provider access, state, execution modes, resilience, budgets, versioning, and operations into a restrained design.
Uses a transactional outbox to make a local state change durably publishable while accepting at-least-once delivery and operating the backlog safely.