Code Room
On-callMediumoc-p109
Subject Incident responseLevel Mid–Senior~20 minCommon in Reliability & on-call interviewsIndustries Technology, Software development

Question

Mid-incident, you follow the runbook, but its steps are outdated and lead you astray (a command no longer exists, or the architecture changed). How do you handle it now and after?

What a strong answer looks like

Stop the bleeding first (mitigate), then form hypotheses from real signals. Separate root cause from symptom, communicate status as you go, and close with what prevents a repeat.

Diagram & narrate the incident
Loading whiteboard…
Run or narrate your approach, then ask the coach.