Skip to contentSkip to footer
  • Community
  • Jobs
  • Companies
  • Salaries
  • For employers
      Notifications

      Loading...

      Elevate your career

      Discover your earning potential, land dream jobs, and share work-life insights anonymously.

      employer cover photo
      employer logo
      employer logo

      Amazon

      Engaged employer

      About
      Reviews
      Pay and benefits
      Jobs
      Interviews
      Interviews
      Related searches: Amazon reviews | Amazon jobs | Amazon salaries | Amazon benefits | Amazon conversations
      Amazon interviewsAmazon Penetration Testing interviewsAmazon interview


      Glassdoor

      • About / Press
      • Awards
      • Blog
      • Research
      • Contact Us
      • Guides

      Employers

      • Free Employer Account
      • Employer Centre
      • Employers Blog

      Information

      • Help
      • Guidelines
      • Terms of Use
      • Privacy and Ad Choices
      • Do Not Sell Or Share My Information
      • Cookie Consent Tool
      • Security

      Work With Us

      • Advertisers
      • Careers
      Download the App

      • Browse by:
      • Companies
      • Jobs
      • Locations
      • Communities
      • Recent posts

      Copyright © 2008-2026. Glassdoor LLC. "Glassdoor," "Worklife Pro," "Bowls" and logo are proprietary trademarks of Glassdoor LLC.

      Company Bowl sample

      Want the inside scoop on your own company?

      Check out your Company Bowl for anonymous work chats.

      Bowls

      Get actionable career advice tailored to you by joining more bowls.

      Followed companies

      Stay ahead in opportunities and insider tips by following your dream companies.

      Job searches

      Get personalised job recommendations and updates by starting your searches.

      Penetration Testing Interview

      10 Nov 2020
      Anonymous interview candidate
      London, England
      No offer
      Neutral experience
      Difficult interview

      Application

      I applied online. I interviewed at Amazon (London, England) in Oct 2020

      Interview

      Applied online. Arranged a call upon one cancellation due to the different time zones. Eventually arranged a call in the evening on my local time. The interview started with the question of my personal experience on: "Describe me a bug you recently found in the code". The thing is my position does not primarily involve any code development and I considered it bad to simply say that, so I improvised. However, that made me quite anxious and had a serious impact on my next answers. Then, I had to solve a problem with using a scripting language. However, it is not specific what is expected on your end so, even though I started with bash, I, then, asked to work with python, which does not look quite well either. Another issue is the fact that you are writing code in a simple online text editor, but the interviewer is going to execute that code, which does not allow any specificities to be omitted. The rest of the questions are outlined below. Long story short, I failed and it is definitely an issue on my end. However, it needs to be noted also that the interviewer was not quite willing to guide the interview process, rather he was looking forward to the end of it. The process is not quite well described in terms of expectations and what you will have to do or write during it and the overall experience ended up being quite stressful. However, again, I believe that primarily was my issue and lack of knowledge.

      Interview questions [4]

      Question 1

      What potentially issue exist with Java deserialization, why can it be exploited and how can it be mitigated?
      Answer question

      Question 2

      Symmetric vs Asymmetric cryptography? Encryption vs Signing? Is it possible for encryption to take place without signing?
      Answer question

      Question 3

      You have a docker setup with various clients files on it. What are the possible attacks there?
      Answer question

      Question 4

      The RFC for the GET request mentions: "The GET method means retrieve whatever information (in the form of an entity) is identified by the Request-URI." What is the possible issue here?
      2 Answers

      Top companies for "Compensation and Benefits" near you

      avatar
      Amazon Web Services
      3.9★Compensation and benefits
      avatar
      Google
      4.5★Compensation and benefits
      avatar
      Delivery Hero
      3.8★Compensation and benefits
      avatar
      Meta
      4.6★Compensation and benefits