Dataford
Interview QuestionsInterview GuidesExperiencesMock InterviewsPricing
Get started
Dataford
Popular roles
Software EngineerData AnalystData ScientistData EngineerBusiness AnalystAI EngineerMachine Learning EngineerProduct Manager
Browse
Browse All RolesEvery role hub, from analyst to MLBrowse All CompaniesCompany-specific interview loopsAll Interview GuidesThe full guide library
Top questions by role
Software EngineerData AnalystData ScientistData EngineerBusiness AnalystAI EngineerMachine Learning EngineerProduct Manager
Top questions by skill
SQLPythonStatisticsMachine LearningA/B TestingSystem DesignGenerative AIProduct SenseMetricsBehavioral
Browse all questions →Try a mock interview
Experiences
Practice
Mock InterviewsTimed interview simulations with feedbackSuccess PathYour 6-week structured planModulesCurated lessons by topicWebinarsTalks from ex-Big Tech data leadsPlaygroundA free-form scratch editor
Learn
BlogInterview strategy and career adviceTech Job Market ReportHiring trends across data and AI rolesFor UniversitiesDataford for career centersAbout DatafordWho we are and how we build
Pricing
Build my plan
Detect Multi-IP Transaction Bursts
00:00
5 left

Detect Multi-IP Transaction Bursts

MediumSQL · PostgreSQL

Problem

Write a SQL query to identify users who have initiated transactions from multiple distinct IP addresses within a five-minute window.

Use the transactions table. A qualifying window begins at a transaction timestamp and includes transactions through five minutes afterward. Ignore transactions with a NULL IP address. Return each user only once, using their earliest qualifying window.

Output

  1. One row per qualifying user with user_id, window_start, window_end, distinct_ip_count, and ip_addresses
  2. Sort by user_id ascending; break ties by window_start ascending

Schema

transactions
ColumnTypeDescription
transaction_idPKINTUnique transaction identifier
user_idINTIdentifier of the user who initiated the transaction
initiated_atTIMESTAMPTimestamp when the transaction was initiated
ip_addressVARCHAR(45)Source IPv4 or IPv6 address
Tablestransactions
Interviewer

Your question is Detect Multi-IP Transaction Bursts. Start with the requirements and the one table in the Question tab.

Run and submit as often as you like. When you're ready, talk me through your approach or go straight to the code.

You need to log in / sign up to run or submit.
CodePostgreSQL
Sign up free to run your codeLog inLn 1
Run your query to see results here.