1. Authorization advanced

    An internal API accepts a customer ID and returns that customer's data. It authenticates the calling service with mTLS. What is the flaw?

    2 min answer authorizationconfused-deputyzero-trust
  2. Compliance Frameworks advanced

    How would you reduce PCI DSS scope for an e-commerce platform, and what does it cost you?

    2 min answer pcicompliancescope-reductiontokenisation
  3. Compliance Frameworks advanced

    PCI DSS assessment covers 40 systems and costs a fortune annually. How would you reduce that architecturally?

    2 min answer pciscopetokenisationcompliance
  4. Encryption advanced

    A file storage platform encrypts data at rest and in transit. A customer asks whether the provider can read their files. What does the honest answer depend on, and what would change it?

    2 min answer encryptionkey-managementend-to-endthreat-model
  5. Identity & Access Management advanced

    A workforce platform holds identity, payroll and device management, and integrates with dozens of downstream systems. What is the central security risk and how is it bounded?

    2 min answer ripplingdeelprivilegeintegrations
  6. Identity & Access Management advanced

    An enterprise platform's permission model has grown to thousands of roles and profiles, and nobody can determine what access a given user actually has. What is the diagnosis and the remediation?

    2 min answer iamrbacabacleast-privilege
  7. Identity & Access Management advanced

    Design the break-glass access mechanism for production. What are the requirements?

    2 min answer accessincidentcontrols
  8. Security Incident Response advanced

    A blockchain infrastructure provider suspects a compromised credential with access to production. What must the response prioritise, and what capability determines how well it goes?

    2 min answer polygonincident-responsecontainmentforensics
  9. Security Incident Response advanced

    A platform discovers that an attacker has held valid credentials for an unknown period. What does the response require beyond containment, and what determines how well it goes?

    2 min answer incident-responseforensicscredentialsdisclosure
  10. Security Incident Response advanced

    Anomalous access to a customer database is detected. Walk me through the first day, and say what determines whether you can answer the regulator.

    2 min answer incident-responsebreachforensicsnotification
  11. Security Incident Response advanced

    You discover an attacker holds valid credentials in your environment. What are your first three actions and what must already exist for them to be possible?

    2 min answer incident-responsecontainmentforensicscredentials
  12. Key Management advanced

    A communication platform adds end-to-end encryption to multi-party meetings. What are the hard problems, and which are cryptographic versus operational?

    2 min answer key-managemente2eegroup-keystrust