AdvancedStaffSecurity, Privacy & Multi-Tenancy55 minutesPro answer

SDV-042

Rotate a multi-level encryption key hierarchy without losing availability

Design envelope-key versioning, lazy and bulk rewrap, compromise response, cache behavior, and evidence for billions of encrypted objects.

EncryptionSecurityZero DowntimeAuditability

Interview prompt

Problem context

A platform encrypts billions of objects with per-tenant data keys wrapped by regional keys. A compliance mandate requires annual rotation and the security team needs emergency compromise response. Re-encrypting every object synchronously is impossible and key-service outages must not take down all reads.

Skills being evaluated

key hierarchy designrotation protocolscompromise containmentavailability trade-offs

The full reasoning guide is part of Pro

The scenario and evaluation focus above remain public. Pro unlocks the structured answer, trade-off analysis, follow-up probes, common weak answers, rubric, related reasoning, and any architecture diagram.

Sign in to continue

What the full guide covers

Clarify the decision
Establish scale assumptions
Functional and non-functional requirements
High-level architecture
Data model and flow
Consistency and transaction boundaries
Failure modes and recovery
Security and privacy
Observability and SLOs
Capacity and cost
Alternatives and trade-offs
Evolution and migration
What Staff and Principal candidates should emphasize