1. OWASP Risks intermediate

    A marketplace hosts seller-generated content including descriptions, images and shop pages. Which common web risks are amplified, and what controls apply?

    2 min answer owaspxssuser-contentcsp
  2. Secrets Management intermediate

    A payments platform's secrets are in environment variables, set once at deployment. What is wrong, and what should replace it?

    2 min answer razorpaysecretsrotationworkload-identity
  3. Secrets Management intermediate

    A team stores credentials in a secrets manager and considers the problem solved. What is still wrong, and what does a genuinely good secrets posture look like?

    2 min answer secretsrotationworkload-identitycredentials
  4. Secure API Design intermediate

    A developer platform's API is used by thousands of external integrators. What security properties must be defaults rather than options?

    2 min answer postmanapi-securitydefaultsscopes
  5. Threat Modelling intermediate

    A commerce platform threat-models its checkout flow. Which threats are usually missed, and what makes a threat model useful rather than ceremonial?

    2 min answer threat-modellingcheckoutabusestride
  6. Threat Modelling intermediate

    A design review shows a threat model with one trust boundary — internet to application. What boundaries are missing?

    2 min answer threat-modellingboundariesreview
  7. Threat Modelling intermediate

    An insurance platform runs a threat modelling exercise that produces a long list nobody acts on. What went wrong, and what makes threat modelling useful?

    2 min answer ackothreat-modellingprioritisationdesign
  8. Threat Modelling intermediate

    Threat modelling is widely recommended and rarely practised sustainably. What makes it fail, and what does a version that survives contact with delivery look like?

    2 min answer threat-modellingstridesecurity-reviewprocess
  9. Tokens & JWTs intermediate

    Your JWTs last one hour. An employee is dismissed. Security asks why they still had system access for 45 minutes. Explain and fix.

    2 min answer jwtrevocationsessions