Interview kitsBlog

Your dream job? Lets Git IT.
Interactive technical interview preparation platform designed for modern developers.

XGitHub

Platform

  • Categories

Resources

  • Blog
  • About the app
  • FAQ
  • Feedback

Legal

  • Privacy Policy
  • Terms of Service

© 2026 LetsGit.IT. All rights reserved.

LetsGit.IT/Categories/Architecture
Architecturehard

Rate limiting — name two strategies and where you can enforce them.

Tags
#rate-limiting#token-bucket#api-gateway
Back to categoryPractice quiz

Answer

Common strategies are token bucket and leaky bucket (or fixed/sliding window). You can enforce limits at the edge/API gateway, load balancer, or in the app (per user/IP), ideally close to the entry point.

Advanced answer

Deep dive

Expanding on the short answer — what usually matters in practice:

  • Context (tags): rate-limiting, token-bucket, api-gateway
  • Scaling: what scales horizontally vs vertically, where bottlenecks appear.
  • Reliability: retries/circuit breakers/idempotency, observability (logs/metrics/traces).
  • Evolution: keep changes cheap (boundaries, contracts, tests).
  • Explain the "why", not just the "what" (intuition + consequences).
  • Trade-offs: what you gain/lose (time, memory, complexity, risk).
  • Edge cases: empty inputs, large inputs, invalid inputs, concurrency.

Examples

A tiny example (an explanation template):

// Example: discuss trade-offs for "rate-limiting-—-name-two-strategies-and-where-yo"
function explain() {
  // Start from the core idea:
  // Common strategies are token bucket and leaky bucket (or fixed/sliding window). You can enf
}

Common pitfalls

  • Too generic: no concrete trade-offs or examples.
  • Mixing average-case and worst-case (e.g., complexity).
  • Ignoring constraints: memory, concurrency, network/disk costs.

Interview follow-ups

  • When would you choose an alternative and why?
  • What production issues show up and how do you diagnose them?
  • How would you test edge cases?

Related questions

Security
How do you protect a public API from abuse?
#rate-limiting#abuse#api
Microservices
Distributed rate limiting: why is it harder than a simple in-memory counter?
#microservices#rate-limiting#redis
Cloud
Rate limiting in the cloud: where can you enforce it and why?
#cloud
#rate-limiting
#waf
Microservices
What is an API Gateway used for?
#api-gateway#routing#security