Quant interview preparation
Prop market making and quantitative research, weighted the way the interviews actually are: probability and expected value, statistics and machine learning, market making logic, programming and options. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it, and every probability answer shows the reasoning path rather than just the number.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 53
- Firms
- 15
- Updated
- September 2026
082Something in your C++ program is overwriting memory it should not. How do you find it?Tower Research CapitalForeign Exchange · London · 2019
Say this
Reach for the sanitisers first. AddressSanitizer catches out-of-bounds writes and use-after-free with roughly a two times slowdown and tells you both the write site and the allocation site. If the corruption is timing-dependent, add ThreadSanitizer for data races.
Then walk it
- Order of tools: compile with -fsanitize=address,undefined and run the failing case. That resolves most buffer overruns and use-after-free immediately. Valgrind memcheck is slower but needs no recompile and catches uninitialised reads that ASan misses.
- If the corrupted location is known but the writer is not, set a hardware watchpoint in gdb on that address with watch, and let it break when something writes. Four watchpoints on x86, which is usually enough.
- If the corruption is not reproducible, make it reproducible before anything else. Record the inputs, pin the threads, disable randomisation, and consider record-and-replay with rr. A bug you cannot reproduce cannot be fixed, only guessed at.
- Common causes to check by inspection while the tools run: writing past the end of a fixed buffer, a dangling reference into a vector that reallocated, a stale pointer into an object that moved, a struct written with memcpy at the wrong size, and two threads writing the same cache line without synchronisation.
- And the systems answer for a production trading process where you cannot run ASan in the hot path: build with sanitisers in a test environment and in a canary, add canary values or guard pages around suspect buffers, and turn on the allocator's own debug checks. I would also say plainly that the fastest fix for a class of these bugs is to stop using raw buffers, because bounds-checked containers and spans eliminate the whole category.
Where candidates lose it
Answering add print statements. That is the answer of someone who has never used a sanitiser, and at a firm running C++ in production it is disqualifying. Name ASan specifically, name the gdb watchpoint technique for a known address, and say how you would make an intermittent bug reproducible before you try to find it.
Expect next
- What does AddressSanitizer not catch?
- How would you debug this in production where you cannot run sanitisers?
- What is a data race and why is it undefined behaviour?
Reported by candidates at Tower Research Capital (Foreign Exchange, London, 2019). Source: Wall Street Oasis.
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

