SecurityBackendDevOps/Cloud

Rate Limiting

Also written as Throttling

Restricting how many requests a user or system can make in a given time window, to prevent abuse, protect against attacks, or keep costs predictable.

Think of it like

Like a nightclub bouncer capping how many people can enter per minute, even if a huge crowd shows up all at once.

Junior or senior?

Junior sounds like

Added rate limiting proactively with no real incident behind it.

Senior sounds like

Can describe the specific incident — abuse, a runaway client, a cost spike — that made it necessary.

Ask them

“Tell me about a time your API needed rate limiting. What triggered adding it?”