1. Compliance Frameworks intermediate

    A global employment platform passes its compliance audits and is repeatedly found to have real security weaknesses. What is the gap?

    2 min answer deelcompliancecontrolsevidence
  2. Compliance Frameworks intermediate

    A payments dataset must stay in the EU. The team reads that as one EU region and pins all storage there across two availability zones. Six months later the business asks for a 15-minute recovery time objective against a regional failure. What did residency actually cost and when did the bill arrive?

    2 min answer data-residencymulti-regionrtokey-management
  3. Compliance Frameworks intermediate

    A vendor platform must satisfy security certification requirements while serving customers across many jurisdictions. How should compliance influence architecture without paralysing it?

    2 min answer compliancecontrolsautomationevidence
  4. Data Classification intermediate

    A consumer finance platform wants to apply controls proportionate to data sensitivity. How should classification work so it actually drives behaviour?

    2 min answer sliceclassificationcontrolsautomation
  5. Data Classification intermediate Multiple choice

    A data platform labels tables as public internal confidential or restricted in its catalogue. Six months on an auditor finds restricted columns in a dashboard that 400 people can open. Which control would have actually prevented it?

    3 min answer data classificationaccess controlgovernancemasking
  6. Data Classification intermediate

    A developer needs to reproduce a bug that only occurs with a specific customer's data. What do you allow?

    2 min answer privacyaccessoperations
  7. Data Classification intermediate

    A platform handles customer addresses, payment details, order history, retailer pricing and shopper location. Why does data classification matter architecturally, and what goes wrong without it?

    2 min answer data-classificationcontrolsresidencyretention
  8. Encryption intermediate Multiple choice

    A regulator asks whether customer data is encrypted. The team says yes, disks are encrypted. Is that a sufficient answer?

    2 min answer encryptionthreat-modelcompliance
  9. Encryption intermediate Multiple choice

    A restricted column must be encrypted in the application before it reaches the database, and support staff must still look customers up by that exact value. 30 million rows and a p95 budget of 200 ms for the lookup. Which design?

    2 min answer field-level-encryptionblind-indexdeterministic-encryptionsearchable-encryption
  10. Encryption intermediate Multiple choice

    Your database is encrypted at rest. An attacker obtains valid application credentials. What does the encryption protect against?

    2 min answer encryptionthreat-modelkey-managementat-rest
  11. Identity & Access Management intermediate

    Forty developers share one service account to access a partner API because the partner charges per credential. What do you do?

    2 min answer identityattributioncontrols
  12. Security Incident Response intermediate

    At 09:00 a customer reports that a report they exported contains another customer's records. You have the on-call. Walk me through your first hour, and tell me what architectural question you would ask on day two.

    3 min answer incident responsemulti-tenancycontainmentforensics