Egress bandwidth spike
Your egress-bandwidth dashboard for a backend service that normally pushes <50 MB/hour outbound shows a sustained 400 MB/hour to an external IP for the last 3 hours, all over HTTPS on 443 to a domain registered four days ago. The service runs in a private subnet and shouldn't be talking to the internet at all except to two known APIs. A dependency was bumped in a deploy 5 days ago. You're on call. Triage and respond.
What a strong answer looks like
Stop the bleeding first (mitigate), then form hypotheses from real signals. Separate root cause from symptom, communicate status as you go, and close with what prevents a repeat.
0:00 of about 40 min
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.