Questions
44 of 46
1What is RAG and why is it preferred over fine-tuning for domain-specific knowledge in production applications?
2What are the core components of a RAG pipeline in LangChain — Document Loaders, Text Splitters, Embeddings, Vector Stores, Retrievers, and Chains?
3What is the difference between semantic search and keyword search and why does RAG rely on semantic similarity?
4What is an Embedding in the context of RAG — what does it represent and why is cosine similarity used to compare them?
5What is a Vector Store and how does it differ from a traditional relational or document database?
6What is the difference between a Retriever and a Vector Store in LangChain — why is the abstraction separation important?
7What is a Document object in LangChain — what are pageContent and metadata fields and why does metadata matter in RAG?
8What are Document Loaders in LangChain and how do you choose the right loader for PDFs, web pages, Notion, Google Drive, or SQL databases?
9What is the difference between RecursiveCharacterTextSplitter and CharacterTextSplitter — when would you use one over the other?
10What is chunk size and chunk overlap in text splitting — how do you decide the right values for your use case?
11How do you handle structured documents like tables, code blocks, or markdown files during the splitting phase to avoid breaking semantic meaning?
12How do you load and split documents lazily (streaming) to handle very large files without running out of memory?
13What is a SemanticChunker and how does it differ from fixed-size character-based splitting?
14How do you preserve and propagate source metadata (filename, page number, URL, timestamp) through the loading and splitting pipeline?
15How do you choose the right embedding model — what tradeoffs exist between OpenAI embeddings, Cohere, HuggingFace, and local models like nomic-embed?
16What is the difference between dense embeddings and sparse embeddings (BM25) — when would you combine both in a hybrid search?
17How do you handle embedding model upgrades in production — what happens to your existing vectors when you switch models?
18How do you efficiently batch embed a large corpus of documents without hitting rate limits or memory constraints?
19What are the tradeoffs between vector stores like Pinecone, Weaviate, Chroma, pgvector, and FAISS — how do you choose for production?
20How do you implement namespace or tenant isolation in a vector store for a multi-tenant RAG application?
21How do you handle incremental updates to a vector store — adding, updating, and deleting documents without full re-indexing?
22What is HNSW indexing and why does it make approximate nearest neighbor search fast at scale?
23What is a similarity score threshold in retrieval and how do you use it to filter out low-confidence results?
24What is MMR (Maximal Marginal Relevance) retrieval and how does it balance relevance with diversity of results?
25What is a MultiQueryRetriever and how does it improve recall by generating multiple phrasings of the same question?
26What is Contextual Compression in LangChain retrieval and how does it reduce noise in retrieved chunks?
27What is a ParentDocumentRetriever — how does it index small chunks but return larger parent chunks to the LLM?
28What is HyDE (Hypothetical Document Embedding) and how does it improve retrieval for vague or abstract queries?
29What is Self-Query Retrieval and how does it allow the LLM to generate structured metadata filters alongside the semantic query?
30How do you implement hybrid search combining dense vector search with BM25 keyword search using EnsembleRetriever?
31What is a Re-ranker (cross-encoder) and where does it fit in the RAG pipeline after initial retrieval?
32What is the difference between Stuff, MapReduce, Refine, and MapRerank document chain strategies — when do you use each?
33How do you build a Conversational RAG chain that maintains chat history and reformulates follow-up questions into standalone queries?
34What is query decomposition and how do you break a complex multi-part question into sub-queries for better retrieval?
35How do you implement Step-Back Prompting in a RAG pipeline to improve retrieval for highly specific questions?
36What is CRAG (Corrective RAG) and how does it add a grading step to decide whether retrieved docs are relevant before answering?
37What is Self-RAG and how does the LLM decide when to retrieve, whether retrieved docs are relevant, and whether the answer is grounded?
38How do you implement a fallback strategy when retrieval returns no relevant documents — how do you avoid hallucination in this case?
39How do you implement RAG evaluation — what metrics like faithfulness, answer relevancy, and context recall do you measure using RAGAS?
40How do you detect and mitigate hallucination in RAG outputs — what role does citation and source grounding play?
41How do you build a citation system that maps each sentence in the LLM's answer back to the exact source chunk it came from?
42How do you handle multilingual RAG — embedding and retrieving documents in multiple languages for a global user base?
43How do you optimize retrieval latency in production — what caching, pre-fetching, or index optimization strategies do you apply?
44How do you implement access control at the retrieval layer — ensuring users only retrieve documents they are authorized to see?
45How do you handle long context RAG — when retrieved chunks exceed the LLM's context window, what strategies do you apply?
46How do you design a RAG pipeline with LangGraph — turning retrieval, grading, and generation into discrete stateful graph nodes?
44 / 46

How do you implement access control at the retrieval layer — ensuring users only retrieve documents they are authorized to see?

Implement access control using ReBAC (Relationship-Based Access Control) integrated with a Zanzibar-inspired permission system, combining pre-retrieval permission checks with post-retrieval metadata filtering.

Access control in RAG requires filtering both during retrieval (pre-filtering) and after (post-filtering). Pre-filtering adds tenant or user permissions as metadata to each chunk at ingestion time, then applies filters directly in vector store queries using filter parameters. Post-filtering validates that all retrieved documents are authorized after retrieval. For complex permission models, integrate a Zanzibar-like permission system (SpiceDB, Ory Keto) that evaluates access relationships at query time. This ensures that the LLM never receives unauthorized content—not through the initial retrieval, nor through any attempt to bypass via prompt injection.

Permission-Aware Retrieval with Metadata Filtering
Access Control Strategies
  1. 1

    Metadata filtering: Add permission metadata to each chunk and filter at query time

  2. 2

    ReBAC integration: Use Zanzibar-inspired systems for complex permission relationships

  3. 3

    Pre-retrieval filtering: Apply filters directly in vector store query to avoid retrieving unauthorized content

  4. 4

    Post-retrieval validation: Double-check all retrieved documents are authorized before passing to LLM

Difficulty: 6/10
Topics: metadata filtering, policy enforcement, scalable retrieval

Scenario Questions

0-2 years experience
  1. 1

    Suppose you have a LangChain RetrievalQA chain that pulls documents from a Pinecone index. How would you ensure that a user only sees documents tagged with their department?

  2. 2

    If you add a filter on the retriever to limit results by a 'visibility' field, what happens when the field is missing on some documents?

  3. 3

    Can you walk me through the code changes you'd make to enforce per‑user access when calling retriever.get_relevant_documents?

2-5 years experience
  1. 1

    You notice that after adding a metadata filter to the retriever, some users still receive unauthorized documents. What could be causing this, and how would you debug it?

  2. 2

    When scaling the system to multiple LLM back‑ends, how would you design the retrieval layer so that access control checks stay consistent across different vector stores?

  3. 3

    Explain the trade‑offs between applying access control in the LangChain retriever versus filtering after the LLM generates an answer.

5-8 years experience
  1. 1

    Design a solution for enforcing fine‑grained document-level permissions in a LangChain pipeline that serves millions of queries per day. Discuss indexing, caching, and latency considerations.

  2. 2

    How would you handle a scenario where a user's role changes while they have an active retrieval session? Ensure no stale data leaks.

  3. 3

    What are the performance implications of pushing access control logic into the vector store query versus applying it in application code, and how would you measure them?

8+ years experience
  1. 1

    At a company‑wide level, we need to migrate from ad‑hoc metadata filters to a centralized policy engine for all LangChain retrieval services. How would you architect this migration to minimize disruption?

  2. 2

    Discuss how you would integrate role‑based access control with multi‑tenant LangChain deployments, considering audit logging, compliance, and cross‑team ownership.

  3. 3

    If a new regulation requires that every document retrieval be logged with the exact permission check outcome, how would you redesign the retrieval layer to satisfy this without degrading throughput?

Follow-up Questions

  • What would you do if the underlying vector store doesn't support metadata filters?
  • How do you ensure the access control logic stays in sync with user role changes?
  • Can you quantify the latency impact of moving the filter from application code to the vector store?