SecurityBackendDevOps/Cloud
Rate Limiting
Also written as Throttling
Restricting how many requests a user or system can make in a given time window, to prevent abuse, protect against attacks, or keep costs predictable.
Think of it like
Like a nightclub bouncer capping how many people can enter per minute, even if a huge crowd shows up all at once.
Junior or senior?
Junior sounds like
Added rate limiting proactively with no real incident behind it.
Senior sounds like
Can describe the specific incident — abuse, a runaway client, a cost spike — that made it necessary.
Ask them
“Tell me about a time your API needed rate limiting. What triggered adding it?”