Topic Drills
Use these prompts for rapid practice. Each answer should include the mechanism, one failure mode, and one practical example.
Python
- What guarantee does a context manager provide, and how does a
yielddependency resemble one? - What is the difference between an iterator, generator, coroutine, and async generator?
- Why are mutable default arguments dangerous?
- When would you use a
Protocolinstead of an abstract base class? - How do exception chaining and
raise ... from exchelp operations? - What does cancellation do at an
awaitpoint? - When do threads help despite the GIL?
- Why can process pools be expensive?
- What belongs in
pyproject.toml? - How do circular imports reveal dependency-direction problems?
HTTP and API design
- Which HTTP methods are safe? Which are idempotent?
- What does 401 mean compared with 403?
- When is 409 more useful than 422?
- What should a 201 response contain?
- How do ETag and
If-Matchsupport optimistic concurrency? - Why should credentials not appear in a query string?
- How does
Content-Typediffer fromAccept? - What does
Vary: Originprotect in a CORS response? - How do you version an API without breaking old clients?
- When is an action resource clearer than CRUD?
- How do you model a long-running operation?
- What belongs in an idempotency-key record?
FastAPI and Pydantic
- How does route declaration order create conflicts?
- What happens when request validation fails?
- Why use response models when Python already has return annotations?
- How does dependency caching affect a database session?
- When should a dependency use
yield? - Why should the application object be created in a factory or composition root?
- How do lifespan and module import differ?
- How do background tasks interact with response completion?
- Why is reading a streaming response body in middleware risky?
- How do you expose multiple authentication schemes in OpenAPI?
- What does
model_validate(..., from_attributes=True)do? - When should a Pydantic validator not query a database?
Databases and SQLAlchemy
- Why does a foreign key need an index on some query paths even though it enforces integrity without one?
- How does column order affect a composite B-tree index?
- What anomalies can occur at Read Committed?
- What is MVCC?
- What is an idle-in-transaction connection?
- How does an identity map affect repeated loads?
- What is autoflush and when can it surprise you?
- Compare
joinedloadandselectinload. - Why can lazy loading break in async code?
- Why should a repository not commit by default?
- When is a savepoint useful in a test or transaction?
- How do you inspect an execution plan safely?
- Why does offset pagination slow down?
- What makes a cursor stable?
- Why must Alembic autogeneration be reviewed?
Authentication and security
- Why is password hashing deliberately slow?
- What claims must a resource server validate in a JWT?
- Why is a signed JWT not secret?
- What is refresh-token replay detection?
- Session cookie or bearer token: what changes in the threat model?
- What is CSRF and when does SameSite help?
- Why is wildcard CORS incompatible with credentialed browser requests?
- How should API keys be stored and rotated?
- How does RBAC differ from resource-level authorization?
- Where can tenant scope be lost?
- How do parameterized queries stop SQL injection?
- How do you handle an uploaded archive safely?
- Which forwarding headers can be trusted?
- How would you respond to a committed secret?
Testing
- What is the difference between a unit and integration test in your service?
- When is a fake better than a mock?
- Why should PostgreSQL queries be tested on PostgreSQL?
- How do dependency overrides hide security bugs?
- How do you isolate database tests without masking commit behavior?
- What should a migration test prove?
- How do you test duplicate webhook delivery?
- How do you test timeout and cancellation behavior?
- What belongs in a contract test for a provider adapter?
- Why can 100 percent line coverage still miss the main risks?
- How do you make factories produce valid but varied data?
- What must a load test observe besides client latency?
Caching, jobs, and messaging
- What is cache-aside?
- What causes a cache stampede?
- When should a cache fail open?
- Why can invalidation after commit still race?
- What does at-least-once delivery require from handlers?
- When is
BackgroundTaskssufficient? - What is the difference between a command and an event?
- Why does an outbox still permit duplicate messages?
- How do acknowledgement timing and visibility timeout interact?
- When is Kafka justified over a task queue?
- How do you prevent a poison message from blocking progress?
- How do you make a scheduled job idempotent?
Deployment and observability
- Why should a container run as non-root?
- What belongs in a multi-stage Docker build?
- How do Uvicorn process count and pool size interact?
- What is graceful termination?
- Why should liveness not depend naively on PostgreSQL?
- What is the trusted proxy boundary?
- How does response buffering affect SSE?
- What does an immutable artifact promotion model provide?
- How do logs, metrics, and traces differ?
- Why are user IDs poor metric labels?
- What is a service-level objective?
- Which signals reveal pool saturation?
- What makes an alert actionable?
- How do you correlate an HTTP request with a worker job?
Architecture and system design
- When does a service layer earn its cost?
- When is a repository only indirection?
- What is a bounded context?
- Why is a modular monolith often a strong default?
- What evidence justifies a microservice extraction?
- How do synchronous call chains affect availability?
- What is a compensating action?
- How do you define data ownership between services?
- How do you migrate a boundary without a flag day?
- What is backpressure and where can it be applied?
- How do you estimate concurrency from traffic and latency?
- What would you degrade first during overload?
- How do you design tenant fairness?
- Which architecture decision deserves an ADR?
- When should two services be merged?
AI backends
- When is SSE better than WebSockets for model output?
- Why does streaming not make a model job durable?
- How do you account for provider work after client disconnect?
- What needs to be versioned with a prompt?
- How do you prevent unbounded model cost?
- Why is model output untrusted input?
- Which fields belong in an AI job record?
- How do you isolate bulk ingestion from interactive chat?
- Where must RAG authorization filters apply?
- How do you re-embed without a mixed index?
- How do you evaluate retrieval separately from generation?
- What lineage is needed to delete a document fully?