Cloud Computing Interview Questions for Freshers (2026): The Gap Between a Certificate and a Deployment

Updated August 2026

Cloud is the topic where the distance between what a fresher resume claims and what the candidate has done is widest, and interviewers know it. "AWS" appears on the skills line after a video course; the follow-up is "what have you deployed, and what did it cost you?" and the conversation frequently ends there. This is not because interviewers are hostile to freshers — it is because the vocabulary is easy to acquire and the experience is not, and one small thing you actually built and can describe outperforms a long list of service names every single time.

On certification, which is the question students ask most and get the least honest answer to: a foundational certificate — AWS Cloud Practitioner, Azure AZ-900 — proves you have the vocabulary. It can help you past an automated filter or a recruiter screen, and some employers value it or will sponsor it once you join, so it is not worthless. What it does not do is survive a technical conversation, because it certifies that you can recognise terms rather than that you have configured anything. Associate-level certifications carry more weight precisely because they are harder to pass without hands-on work. The sequence that actually pays is to build something first and certify second, not the reverse.

One practical warning before you start, because it causes real financial harm to students every year: set a billing alert on the day you create the account, before you launch anything. Free tiers are limited by service, by month and by account age, several commonly-used resources are not free at all, and a forgotten instance or an idle gateway quietly accrues charges. Deleting what you spun up after each practice session is a habit, not an optional tidiness — and knowing that this is how cloud costs actually behave is itself something interviewers respect.

Frequently asked questions

What is cloud computing, and what does an organisation actually gain from it?

Cloud computing is on-demand access to computing resources — servers, storage, databases, networking — over the internet, paid for by usage rather than owned outright. The genuine gains are that capital expenditure becomes operating expenditure, capacity can be provisioned in minutes rather than procured over weeks, and you can scale with demand instead of buying for peak. State the trade-offs too, because that is what separates a considered answer from a marketing one: costs can exceed on-premises at steady high utilisation, you inherit a dependency on someone else's availability, egress charges and vendor lock-in are real, and data residency may be a regulatory constraint. An interviewer hearing both sides reads you as someone who has thought about it.

Explain IaaS, PaaS and SaaS with examples.

IaaS gives you virtualised infrastructure — compute instances, storage, networking — and you manage the operating system, runtime and application on top: EC2 and Azure Virtual Machines sit here. PaaS gives you a managed platform where you deploy code and the provider handles the operating system, patching and scaling: Elastic Beanstalk, Azure App Service, Heroku. SaaS is finished software delivered over the internet, where you manage nothing but your data and users: Gmail, Salesforce, Microsoft 365. The useful framing is that each step up hands more operational responsibility to the provider and takes away more control, and the right choice depends on how much of that control you actually need.

What is the difference between public, private, hybrid and multi-cloud?

Public cloud means shared infrastructure operated by a provider and available to anyone — the standard model. Private cloud means infrastructure dedicated to one organisation, whether hosted on their premises or by a provider, chosen for regulatory, data-residency or control reasons. Hybrid means deliberately connecting the two, commonly keeping sensitive data on private infrastructure while using public cloud for scale or for less sensitive workloads. Multi-cloud means using more than one public provider, usually to avoid lock-in or to take a specific capability from each — and worth mentioning as genuinely harder to operate, since teams need expertise in every platform they use.

What is a region, an availability zone and an edge location — and why does the distinction matter?

A region is a geographic area containing multiple data centres. An availability zone is one or more physically separate data centres within a region, with independent power, cooling and networking, connected to the other zones by low-latency links. Edge locations are a much larger set of smaller sites used for content delivery and caching close to users. Why it matters: deploying across multiple availability zones protects you from a single data centre failure and is the standard high-availability pattern, while region choice affects latency to your users, price — regions are priced differently — and legal compliance where data must remain in-country. A single-zone deployment is a single point of failure regardless of how many instances you run in it.

What decisions do you make when launching a virtual machine?

The machine image, which determines the operating system and any pre-installed software; the instance size, which sets CPU, memory and network capacity and is the main cost lever; the region and availability zone; the network placement, meaning which virtual network and subnet, and whether it needs a public address at all; the firewall rules governing inbound and outbound traffic; the storage attached, its type and size and whether it persists when the instance is terminated; and the key pair or credential mechanism for access. The two freshers most often get wrong are placing something in a public subnet that has no reason to be reachable, and opening administrative access to the entire internet rather than to a known address.

What is object storage, and how does it differ from block and file storage?

Object storage keeps data as objects — the content plus metadata plus a unique identifier — in a flat namespace accessed over HTTP, which makes it ideal for images, backups, logs, static websites and anything large and write-once-read-many. It is not a filesystem and you cannot modify part of an object in place. Block storage presents raw volumes attached to a single instance, which the operating system formats and uses like a disk — this is what a database or an operating system needs. File storage presents a shared filesystem that multiple instances can mount concurrently. The short version for an interview: object for unstructured data at scale, block for a single machine that needs a disk, file for sharing a filesystem across machines.

Scaling up versus scaling out, and what is elasticity?

Scaling up, or vertical scaling, means making a single machine larger — more CPU or memory. It is simple and requires no application changes, but has a hard ceiling and usually requires downtime to resize. Scaling out, or horizontal scaling, means adding more machines behind a load balancer, which has no practical ceiling and improves fault tolerance, but requires the application to be stateless or to handle shared state properly. Elasticity is scaling out and back in automatically in response to demand, which is the property that actually saves money — scalability is the ability to grow, elasticity is growing and shrinking without someone deciding to. Being able to state that distinction cleanly is often the whole question.

What does a load balancer do?

It distributes incoming traffic across multiple backend instances, which serves three purposes: spreading load so no single machine saturates, providing high availability by routing away from instances that fail its health checks, and giving clients one stable entry point regardless of how many machines sit behind it. Worth adding: health checks are the mechanism that makes failover work, so a misconfigured health check is a common cause of an outage that looks mysterious; and load balancers commonly terminate TLS, which is where certificates are usually managed. Mention session handling if you can — sticky sessions versus keeping the application stateless, with stateless being the cleaner design.

Virtual machines versus containers?

A virtual machine virtualises hardware: each VM runs a full guest operating system on a hypervisor, giving strong isolation at the cost of size and startup time measured in gigabytes and minutes. A container virtualises the operating system: containers share the host kernel and package only the application and its dependencies, so they are megabytes and start in seconds, with weaker isolation as the trade-off. The practical consequence is density and speed — you fit far more containers than VMs on the same hardware and can start and stop them quickly, which is why they suit microservices and CI pipelines. The honest caveat to mention is that sharing a kernel means container isolation is a weaker boundary than a hypervisor.

What are Docker and Kubernetes?

Docker is a platform for building and running containers: a Dockerfile describes an image, the image is built and stored in a registry, and a container is a running instance of that image. Its value is that the same image runs identically on your laptop, in CI and in production, which removes the works-on-my-machine class of problem. Kubernetes is an orchestrator for containers across many machines: it schedules them, restarts what dies, scales replicas up and down, handles service discovery and load balancing between them, and rolls out new versions gradually. The one-line relationship: Docker packages and runs a container; Kubernetes runs thousands of them across a fleet and keeps them in the state you declared. As a fresher, having built and run one Docker image yourself is worth far more than reciting Kubernetes architecture.

What is serverless, and when is it the wrong choice?

Serverless means running code without provisioning or managing servers — you supply a function, the provider runs it in response to an event and bills you per invocation and duration, scaling automatically to zero when idle. AWS Lambda and Azure Functions are the common examples. It suits event-driven, bursty or infrequent workloads, scheduled jobs and glue between services. Where it is wrong: long-running work that exceeds execution limits, latency-sensitive paths where cold starts hurt, workloads at sustained high volume where per-invocation pricing overtakes a reserved instance, and anything needing persistent local state or specialised hardware. Naming the cold-start problem and the execution timeout shows you have thought past the marketing.

Explain the shared responsibility model.

Security of the cloud is the provider's responsibility; security in the cloud is yours. The provider secures the physical facilities, the hardware, the hypervisor and the managed service infrastructure. You are responsible for your data, your identity and access configuration, your network rules, your operating system patching where you manage the OS, and your application code. The boundary moves with the service model — with IaaS you patch the operating system, with a managed database the provider does, with SaaS almost everything but your data and access control sits with the provider. The reason interviewers ask is that most publicised cloud breaches are customer-side misconfiguration, typically a storage bucket or a database left publicly readable, not a provider failure.

What is IAM, and what does least privilege mean in practice?

Identity and Access Management controls who can do what to which resources. Users, groups and roles are granted permissions through policies, and the principle of least privilege means granting only the permissions actually needed and no more. In practice: give applications and instances a role rather than embedded access keys, so credentials are temporary and rotated automatically; use groups for people rather than attaching policies to individuals; avoid wildcard permissions on all actions and all resources; enable multi-factor authentication, especially on the root account, and then stop using the root account for daily work. If you can add that access keys should never be committed to a repository, and what to do if they were, you are answering a security question rather than a definition.

What is a security group, and how does it differ from a network ACL?

A security group is a virtual firewall attached to an instance. It is stateful, meaning a response to an allowed inbound request is automatically permitted outbound, and it supports allow rules only — anything not explicitly allowed is denied. A network ACL operates at the subnet level, is stateless so inbound and outbound rules must both be written, and supports explicit deny rules, which makes it useful for blocking specific addresses across a whole subnet. The practical guidance worth stating: security groups are the primary control most of the time, and the classic mistake is opening administrative ports to the whole internet rather than to a specific address range.

High availability, fault tolerance and disaster recovery — what is the difference?

High availability means the system stays operational through common failures, usually by running redundant components across availability zones with automatic failover, accepting a brief disruption. Fault tolerance is stronger: the system continues without interruption when a component fails, which requires more redundancy and costs more. Disaster recovery is the plan for restoring service after a major event, measured by how much data you can afford to lose and how quickly you must be back — the recovery point and recovery time objectives. The interview-friendly summary is that high availability keeps you running through the failures you expect, and disaster recovery gets you back after the ones you do not.

What are the main pricing models, and how do people waste money?

On-demand charges by the second or hour with no commitment and is the most expensive per unit — right for unpredictable or short-lived workloads. Reserved instances or savings plans commit you to a term in exchange for a substantial discount, right for steady baseline load. Spot instances use spare capacity at a large discount but can be reclaimed with little notice, right for fault-tolerant batch work. Where money actually leaks: instances left running after a test, unattached storage volumes and idle addresses that bill regardless of use, over-provisioned instance sizes chosen by guesswork, data transfer out of the cloud, and forgotten resources in a region nobody looks at. Mentioning tagging and budget alerts as the countermeasures shows operational awareness.

What is a VPC, and what is the difference between a public and a private subnet?

A VPC is your own logically isolated network within the cloud, with an address range you define. Within it you create subnets, each in an availability zone. A public subnet is one whose route table sends internet-bound traffic to an internet gateway, so resources there can be reachable from the internet. A private subnet has no such route; resources in it can reach the internet only through a NAT gateway for outbound traffic, and cannot be reached directly from outside. The standard pattern to describe is a load balancer in the public subnet with application servers and databases in private subnets — and the standard fresher mistake is putting a database in a public subnet because it was easier to connect to.

What is a CDN, and when would you use one?

A content delivery network caches copies of your content at edge locations close to users, so requests are served from nearby rather than from your origin. The benefits are lower latency for geographically dispersed users, reduced load and egress cost at the origin, and absorption of traffic spikes. It is most obviously right for static assets — images, CSS, JavaScript, video — and can also cache API responses where they are cacheable. The detail worth adding is cache invalidation: content is served from cache until it expires or is explicitly invalidated, which is why a deployment sometimes appears not to have taken effect, and why asset filenames are usually versioned.

How do you know something is wrong in a cloud environment?

Through monitoring, logging and alerting, and being able to name all three separately is the point. Metrics such as CPU, memory, request rate, error rate and latency are collected by the platform monitoring service and charted; logs from the application and platform are centralised so you can search them rather than logging into machines; alarms fire on thresholds and notify someone. Beyond that, health checks let a load balancer act automatically, and distributed tracing follows a single request across services. If you have deployed anything yourself, mention the one alarm you set — even a billing alarm — because a candidate who has configured any alert at all has done more than one who can only list the services.

Have you deployed anything to the cloud yourself?

This is the question the rest of them are really building to, and a small honest answer beats a large vague one. Describe something specific: a static site on object storage behind a CDN, an application on a single instance with a managed database, a container image you built and ran, a scheduled function. Say what you chose and why, what broke — a security group that blocked you, a bill that surprised you, a deployment that would not start — and what it cost. If you have not deployed anything yet, say so directly and describe what you are doing about it this month; that is far better received than a list of services recognised from a course. One deployed project with a real story behind it is the strongest thing a fresher can bring to a cloud conversation.

Is an AWS or Azure certification worth it for a fresher?

Partly, and it depends what you expect from it. A foundational certificate proves vocabulary and can help past a keyword filter or a recruiter screen, and some employers value it or will sponsor certification once you join — so it is not wasted. What it will not do is carry a technical conversation, because it certifies recognition rather than configuration. Associate-level certifications are respected more precisely because passing them without hands-on practice is difficult. The sequence that works: use the free tier to build and deploy something small, then certify on top of that experience, so the certificate documents what you can do rather than substituting for it. If you are choosing between spending on a certificate and spending a month building and deploying a project, build the project.

Don't just read Cloud (AWS/Azure) questions — get asked them

Phiny's AI interviews you on exactly these topics, follows up on weak answers, and tells you what a stronger answer looks like. Text interviews are free and unlimited.

Start a free AI mock interview

How to prepare

Where these questions get asked