Another way to think about it is that these interview processes often have a ~ 1% acceptance rate, and the softball questions typically filter 80-90% of candidates.
So, yeah, it sucks for a qualified candidate if they fail half their interviews, but they'll end up getting a job somewhere. That's much better for them than working at a company where 99% of the engineers can't perform basic coding tasks or explain how products in their industry segment are designed.
Ah, the secretary problem: https://en.m.wikipedia.org/wiki/Secretary_problem
What does the average skill level in the pool converge to over time?
(This might be too hard for a whiteboard problem.)
A written engineering competency test (basically, an industry-standard set of whiteboard questions) sounds good, but, having hired credentialed-but-incompetent engineers from other fields, I can definitely say it helps a lot less than you'd think.
I could list many more sub-disciplines of cybersecurity, but I'm already up to five (and haven't even mentioned cryptography!). None of the skill sets from the five I mentioned really translate well to each other.
Also, what purpose would having a cert for a programming language serve? For things like C++ and JavaScript, there are so many sub-dialects that the cert wouldn't say much about whether you could write inside a particular code base. For things like rust and go, the certificate would need to expire every few years.
Also, it takes an experienced developer a day or two to pick up a new language. Getting a certificate for a language would take longer than that. That lands us where we are right now, where such certifications exist, but they're simultaneously too much trouble to be worth it, and also not worth the paper they're printed on.