Policy Engine Fundamentals
Every policy engine splits deciding from enforcing, places that decision somewhere in delivery, and must still answer when the engine is unreachable. Interviewers open here before naming tools.
on this pageshowhide
explore
- Decision Model15 questions
- PDP, PEP and PIP4 questions
- Rule or Ad-Hoc Script4 questions
- What the Engine Sees3 questions
- Rule Language Styles4 questions
- Enforcement Points and Modes13 questions
- Where a Check Runs3 questions
- Preventive vs Detective4 questions
- Audit, Warn, Enforce3 questions
- Platform-Native Controls3 questions
- Acting on the Answer11 questions
- Fail Open or Closed4 questions
- What a Denial Carries3 questions
- Where Policy Stops4 questions
questions
page 2 of 2Which policy violations can no pre-change check ever catch, however you place the gate?
basics
~20 sViolations where nothing changed. A gate fires on a proposed change, so a resource that becomes non-conforming while sitting still — a certificate passing its expiry, a vulnerability disclosed later — produces no event at all.
Your bots and dashboards parse denial message text — what breaks when you reword the message?
basics
~20 sAnything keyed on the sentence breaks silently: suppressions stop matching, dashboards split one rule into two series, dedupe fails. Nothing errors — the wording was an undocumented API. Give consumers stable fields and declare the message unstable.
Your policy service is healthy and answering fast but loaded an empty rule set - how do you detect that?
basics
~10 sHealth checks only prove the process is up. Detect it behaviourally: evaluate a synthetic input that must always be denied, continuously, and treat an allow on that probe as an outage.
Your cloud provider's native control already blocks public IPs; should you duplicate that rule in your own engine?
basics
~20 sUsually yes, but only as a pre-flight duplicate that gives earlier, better-worded feedback. The native control stays the enforcement; the duplicate is advisory, never proof of compliance, and must handle plan values that are unknown until apply.
Which rule-language style should a platform team standardise on for its policy guardrails?
basics
~20 sThere is no universal answer: you are choosing who can author and review guardrails for years. Cover the bulk with a reviewable restricted style, keep one escape hatch for rules that need quantification, and optimise for the second reader.
Teams keep shipping deploy paths that bypass your enforcement point — how do you decide where enforcement should live?
basics
~20 sSite enforcement where coverage does not depend on anyone remembering. A guard in each tool gives better messages but must be re-adopted forever; a chokepoint every change traverses buys coverage at the cost of late feedback and one shared failure domain.
As security lead, what justifies adopting a policy engine when configurable scanners and shell checks already work?
basics
~20 sAdopt when the rule set is the artifact: conditions no shipped catalogue covers, one rule holding at several enforcement points, readers outside the team. If the need is only toggling existing checks, it is a linter with a config file.
Your policy program's human-review queue is the bottleneck — how do you decide which decisions stay with people?
basics
~20 sTreat review capacity as a fixed budget. Automate every decision the artifact fully determines, spend the remaining review on the few classes where necessity genuinely matters, and explicitly accept the rest rather than queueing work nobody will do.
Your policy has run in audit mode for nine months with 400 open findings - what do you do?
basics
~20 sNine months of unread audit output is a log, not a control. Establish what any row ever caused, treat the 400 as the price of enforcing the rule, then give the report an owner, narrow its scope, or remove it.
showing 31–39 of 39