Shadowing Practice: Excellent 2 Years AWS DevOps Engineer Mock Interview with Questions and Answers | Cloud | Docker - Learn English Speaking with Video

Les maken...
1
hi welcome sarap to the interview
2
and yeah i'm putting a cv in front of me
3
and yeah so just to let you know
4
that this call will be recorded uh for on the social media like youtube and others
5
and that you are okay with
6
that yeah yeah i'm okay with it okay all right uh
7
so yep uh i've got your cv in front of me
8
so why don't we start up with your career progression and
9
and then we'll have some follow-up questions yeah like first of
10
all thanks a lot for this uh opportunity you know i
11
really appreciate it uh my name is uh i will start with how i got into the devops and cloud
12
technology domain so i did my bachelor's of engineering in mechanical field but whilst i I was in third year, I got interested into the computer science.
13
So then I started learning about the Python, basics of Python.
14
And then later during the COVID period, that's when I met my mentor.
15
He taught me a lot of DevOps and cloud technologies.
16
And the most important thing he did was not only taught, but he created my interest in that field genuinely.
17
So I really followed that.
18
And whilst I was in fourth year, I got my opportunity in one of the largest consultancy company in india
19
and since then i've been working there as a devops
20
and cloud engineer uh for two and two year
21
and four months as of now
22
so that's a little bit about my work uh related things
23
uh about my personal things i live in the town of
24
maharashya uh my hobbies are like i like to read books i also like to work out
25
and just stroll in the nature
26
so yeah that's a little bit about me awesome awesome all right
27
so i see from your resume with sort of that you have
28
experience in aws code pipeline cicd python
29
and lambda also used amazon quicksight for visualizations and dashboard
30
so how about uh how about docker
31
and kubernetes yeah i also know a docker
32
and Kubernetes okay all right all right let's start up with some of the aws questions
33
so i'll start right from the basics uh
34
so in terms of aws security
35
so there's something called as knuckles yeah uh can you tell me more about knuckles
36
and how does it how does it differ from subnets yeah
37
so knuckles are the firewalls uh applied at the subnet level
38
uh there is another thing called a security group in aws
39
which somehow relates to it secret but there is a difference
40
that knuckles are stateless so it means
41
that you have to specify specifically the inbound as well as outbound rule whether as the security groups
42
which are attached at the individual resource level like instances uh they are stateful
43
so you just have to mention like inbound and they will automatically gather
44
that outbound is also allowed so that's what an actor is right
45
now in terms of your ec2 uh there is something called as volumes which can be attached
46
right yes you've got elastic black block stores
47
and volumes okay what are the different types of volumes and
48
and what they're used for yeah
49
so like volumes are the like buses are mounted for having the persistent storage to our EC2 servers
50
and the block storage is the EBS that AWS offers
51
in terms of different types of volumes so there are like GP2
52
which are like SSD based then there are IOPS heavy volumes
53
so where you can have a if you want the have application
54
that has heavy read io then you can use the iops
55
type of volumes then there are also some machine learning related uh volumes i guess i don't remember them particularly
56
but yeah so these are some types of volumes so
57
i'll just give you a scenario and you can explain me on the on the questions on it
58
So let's say you've got a three tier or a four tier application.
59
And you are asked to design the application from scratch.
60
So you've got the app layer, you've got an API layer, you've got the business logic, you've got web layer, you've got databases, you're using S3.
61
So these are the same sort of application.
62
So in terms of cloud security how would you secure an application
63
and what are the different attributes
64
that you would have in your application to make it uh consistently secure okay
65
so let's start with the things that i will include uh
66
so first is database layer second is application layer
67
and third is suppose the client accessing the things from internet
68
so that's 3d
69
so i would probably use a api gateway application load violancer
70
in this architecture where i will put just the alb
71
or api gateway in the public subnet where it has access to the external internet
72
and i will put my app server in different private subnet
73
and i will put my database server in different private subnet
74
and then just connect my api gateway alb to the private web server
75
and web servers will have access to the database servers privately
76
and yeah like and the clients can access my application on on the ip address
77
or domain name of the alb which are mapped to it
78
so that is how i would uh like architect it okay are there any other security measures
79
that you can think of yeah like we can have the like
80
if your web server needs access to the database
81
and suppose your database is in rds
82
so you can have a proper im permissions i am in instance profile for your instances in web servers.
83
Also, you can have proper knuckles, the security groups following the least privileges rule as the AWS suggested.
84
So those are some of the security things that you can take in consideration.
85
Anything else that you can think of?
86
You can also add the AWS WAP or something like that
87
if you want the extra security if you want ddos protection
88
so maybe you can use vap and uh
89
if you want to like check the your instances for like uh security vulnerability then maybe use the aws inspector
90
or something like
91
that okay last chance to say something else ah looking for one more point you did well
92
but one more point there is uh ppc there is subnet it's alb uh security groups is there im is there
93
uh maybe like storing the database passwords or something like
94
that you can use the secrets manager for
95
that yeah how about how about you how would you secure a data tell me about data encryption So data encryption,
96
if it's in transit, then you can use the obviously SSL for that SSL certificates.
97
And if it's at the rest, then you can, in terms of AWS, you can use a service like AWS KMS, where you can have different options for managing the keys.
98
Either AWS can manage it or like you can manage it and you can encrypt the data at rest using both keys.
99
Okay.
100
Can you tell me the difference between server-side encryption
101
and client-side encryption yeah i would say server-side encryption is something
102
that uh we do like as a app server where like suppose data is address
103
so that's where you are uh encrypting your data
104
so that's i would say server-side encryption and client-side encryption is something
105
that if client is sending the data then you're using the ssl uh key that
106
public key to encrypt the data so i would say that would be client-setting okay
107
all right uh now coming back to tell me tell me why would you why would you need auto scaling
108
and what are the different types of auto scalings available uh
109
so auto scaling is required if you have a varying terms of traffic to your applications
110
and you want to automatically scale your instances
111
or containers whatever uh type of deployment you have done and uh
112
so you don't need manual intervention suppose the traffic is uh exceeding beyond uh what your cp levels can handle
113
so you don't need to manually increase go
114
and increase the number of servers and set up everything
115
so for that we can use something like auto scaling groups where you already have the pre-configured launch templates
116
that uh and you can give it a various metrics
117
so asg can scale based on like a metric base
118
so like uh suppose average cpu utilization it can also you
119
like scale based on maybe number of requests going to per instance
120
so that is another thing
121
or you can create your own custom metric uh whatever you want and then scale based using that metric for your needs.
122
Okay.
123
Now, have you done any sort of monitoring on any applications?
124
I have not done as per se, but I use CloudWatch whenever I like require to like check something if something has happened or something,
125
but I haven't done specifically monitoring.
126
I do created the dashboards using quicksight uh uh
127
which is the native aws services where we have monitored the like things like cost of our accounts
128
and like uh different s3 bucket size
129
and everything else okay all right can you explain me this term connection draining connection draining
130
so basically it means
131
that your connection is going to die like it's it's finishing up all the things
132
and it's draining it's removing the connection so what does it do
133
uh connection training uh you're talking in terms of specific something
134
or just general term connection so so if an application is going to die what does the connection draining do
135
uh so it if there are any pending requests it will finish up those requests
136
and then it will go down it will close
137
that connection okay yep right all right uh now let's talk something about on the docker
138
and kubernetes so we do we do have docker can you explain me the role of kubernetes in docker
139
so kubernetes the docker container orchestration platform what it means is
140
that it comes on top of docker
141
so docker natively does does not provide things like auto scaling auto healing
142
or uh maybe load balancer type of things uh
143
which the any enterprise level of application would require
144
so that's where a kubernetes come it adds a lot of features
145
that an enterprise require in order to operate their application uh docker does have something called docker swarm
146
but it's not i would say uh like uh fulfills the
147
requirement needed for the enterprise level of application you can use it for a small application
148
but i won't say for enterprise okay
149
so now in kubernetes there is something called as image pull policy yeah okay can you tell me about that
150
so image pull policy is uh suppose you have created a docker file
151
and you want to specify your docker file that
152
when do you pull the image so you can mention in image pool policy
153
that if the image is not present locally then you can pull it from the registry
154
okay and what are the different values that it accepts ah i know one
155
because i have used that one that is
156
if not present in current repository
157
but for others maybe i'll need to like look up in documentation yeah that's all right
158
so there are two more always and never yeah yeah all right
159
so what do you understand by service in kubernetes and how many different types of services are there
160
uh so service is used uh to offer features like i said load balancing It also has a feature called auto discovery.
161
So it automatically discovers the new instances coming up in your cluster for that specific application.
162
And it does that by using the thing called as selectors and labels.
163
Our services has three types.
164
The first is the cluster IP, which is default.
165
It means that whatever service you are exposing to the external world, sorry, whatever services you're exposing, it's only available within the cluster itself.
166
Second is the node port, which means that the services are available to the clients
167
or the servers that has access to the node on which the Kubernetes cluster is running.
168
And third is the load balancer where the cloud providers come
169
in picture where you can expose it to the external world
170
by using external application load balances like alb all right now in kubernetes you have got deployments and you've got demon sets
171
yeah can you tell me the difference between both of them
172
i remember deployment i don't remember demon set to be honest the deployment is basically for uh
173
if you want to deploy your application
174
and have the capability as i say auto healing or auto scaling so that's when you can use our deployment In deployment,
175
you can mention different strategies like rolling deployment or maybe blue-green deployment, something like that.
176
So that's what we use the deployment.
177
I can't remember Devon set.
178
I have read about that, but I have not used it.
179
All right, so deployment makes the pod available in any node, but Devon set, it makes sure that the replica runs in each and every node in the custom.
180
Okay, okay.
181
Okay.
182
Now about RDS, can you tell me the different types of SQL and NoSQL databases and what's the difference between them?
183
RDS is the service offered by AWS called Relational Database Services.
184
So relational means the SQL, which means the structured databases.
185
So that has various things like PostgreSQL, then MySQL, MSSQL.
186
like that.
187
And the other type of database service is the NoSQL type, which is things like DynamoDB or like MongoDB.
188
So where your data is not structured
189
and the data is stored in a key value kind of format rather than the structured column-wise format in SQL.
190
Okay.
191
Any more differences that you can think of?
192
You can like, NoSQL is very scalable, like DynamoDB, you can store like millions and billions of record in it.
193
And it's very resilient in terms of it, whereas your MySQL is not meant for that purpose.
194
all right
195
so now coming back to your experience can you tell me
196
about a about a scenario where you really struggled in some of the cases
197
or something that was very hard to do and then what happened to
198
that finally did you achieve it or not okay um
199
so yeah um like recently there was a once as i might have mentioned in my resume
200
that i've also worked on security things so there was recently one finding
201
that came that our clients had lots of lambda functions running on the aws lambda
202
and all of them were using the runtimes
203
which were deprecated by the aws so
204
that means there were no security patches nothing
205
and it could be vulnerable to the security vulnerabilities
206
and they were around 1300 functions which our clients had on lambda
207
and uh no one like i took the responsibility to upgrade it then uh
208
and 850 were around pythons and rest of the were of node.js
209
so for node.js i took help of someone else in my
210
team who uh has the experience on node.js whether as python i myself have uh the experience
211
so i did them on my own so the challenges i faced in
212
that was their lambda so there are two times the types of functions
213
so one that uses the layers and one
214
that does not use this layer so the one
215
that does not use this layer it was easy to upgrade them
216
so i just created a simple python script and
217
because the python syntax for 3.7 and 3.9 was almost similar there were no differences
218
or nothing that needs to be changed so
219
that i completed like in just few days
220
and then there were the next set of functions
221
that were the layers one saying
222
that i had to like done do some manual things also where like i automated the process of creating
223
and updating layers by using the aws cli so
224
layers are updated
225
but then i had to contact to the various team those were handling those applications uh those functions
226
and then yeah so it was like a big process
227
and at first i thought like 1300 functions that's a lot
228
and like how can i complete this but it needed to do
229
that so yeah i completed it and i'm almost at the end
230
so i have around 150 functions remaining out of those 1300
231
and yeah i will be finishing it in just few days okay that.
232
All right, I think I'm done with the questions and answers.
233
So my feedback to you that you did pretty well.
234
You answered almost all the questions.
235
And yep, so I'll be closing up this recording now.
236
And I'll be giving you more feedback after the recording is done.
237
Thanks for your time.
238
Yeah, yeah, thank you.
239
Thank you.

Context & Background

This video features a mock AWS DevOps engineer interview, where a candidate shares their career journey—from a mechanical engineering background to a 2+ year role in cloud technology—and answers technical questions about AWS, Docker, and more. The dialogue is natural, with conversational flow and industry-specific terms, making it perfect for English learners looking to practice both daily communication and professional vocabulary.

Top 5 Phrases for Daily Communication

  • "I really appreciate it" – A polite way to thank someone for an opportunity, great for formal or casual settings.
  • "whilst I was in third year" – A natural way to connect past actions to a specific time, useful for storytelling.
  • "that's a little bit about me" – A friendly closing for self-introductions, helping you wrap up smoothly.
  • "how about docker and kubernetes?" – A conversational transition to a new topic, perfect for keeping dialogues flowing.
  • "so that's what an actor is right now" – A casual way to confirm understanding, ideal for clarifying points in discussions.

Step-by-step Shadowing Guide

Ready to practice with this video? Here's how to use shadowspeak to boost your English speaking: Step 1: Watch the first 30 seconds, pausing to repeat short phrases like "hi welcome sarap to the interview"—focus on matching the tone and speed. Step 2: Pick 2-3 technical terms (e.g., "AWS Code Pipeline," "Docker") and say them aloud, mimicking the speaker's clarity. Step 3: Shadow the candidate's self-introduction in one go, aiming to replicate their natural rhythm. This video is a goldmine for shadow speak practice because it blends everyday conversation with professional language, giving you quick wins in both areas. With consistent practice, you'll notice your fluency improve—so hit play and start shadowspeaks today!

Learning English with videos like this makes practice fun and practical. Whether you're prepping for interviews or just want to sound more confident, this dialogue offers real-world phrases you can use immediately. Start small, stay consistent, and watch your progress soar!

Wat is de Shadowing-techniek?

Shadowing is een wetenschappelijk onderbouwde taalleermethode die oorspronkelijk is ontwikkeld voor professionele tolkentraining en gepopulariseerd door polyglot Dr. Alexander Arguelles. De methode is eenvoudig maar krachtig: je luistert naar native Engelse audio en herhaalt het onmiddellijk hardop — als een schaduw die de spreker volgt met slechts 1–2 seconden vertraging. In tegenstelling tot passief luisteren of grammaticadrills, dwingt shadowing je hersenen en mondspieren om echte spraakpatronen tegelijkertijd te verwerken en te reproduceren. Onderzoek toont aan dat het de uitspraaknauwkeurigheid, intonatie, ritme, verbonden spraak, luisterbegrip en spreekvaardigheid aanzienlijk verbetert — waardoor het een van de meest effectieve methoden is voor IELTS Speaking-voorbereiding en echte Engelse communicatie.

Shadowing-techniek: lees de volledige stap-voor-stap-gids →