1. Authorization advanced

    An internal API accepts a customer ID and returns that customer's data. It authenticates the calling service with mTLS. What is the flaw?

    2 min answer authorizationconfused-deputyzero-trust
  2. Compliance Frameworks intermediate

    A global employment platform passes its compliance audits and is repeatedly found to have real security weaknesses. What is the gap?

    2 min answer deelcompliancecontrolsevidence
  3. Compliance Frameworks intermediate

    A vendor platform must satisfy security certification requirements while serving customers across many jurisdictions. How should compliance influence architecture without paralysing it?

    2 min answer compliancecontrolsautomationevidence
  4. Compliance Frameworks advanced

    How would you reduce PCI DSS scope for an e-commerce platform, and what does it cost you?

    2 min answer pcicompliancescope-reductiontokenisation
  5. Compliance Frameworks advanced

    PCI DSS assessment covers 40 systems and costs a fortune annually. How would you reduce that architecturally?

    2 min answer pciscopetokenisationcompliance
  6. Data Classification intermediate

    A consumer finance platform wants to apply controls proportionate to data sensitivity. How should classification work so it actually drives behaviour?

    2 min answer sliceclassificationcontrolsautomation
  7. Data Classification intermediate Multiple choice

    A data platform labels tables as public internal confidential or restricted in its catalogue. Six months on an auditor finds restricted columns in a dashboard that 400 people can open. Which control would have actually prevented it?

    3 min answer data classificationaccess controlgovernancemasking
  8. Data Classification intermediate

    A developer needs to reproduce a bug that only occurs with a specific customer's data. What do you allow?

    2 min answer privacyaccessoperations
  9. Data Classification intermediate

    A platform handles customer addresses, payment details, order history, retailer pricing and shopper location. Why does data classification matter architecturally, and what goes wrong without it?

    2 min answer data-classificationcontrolsresidencyretention
  10. Encryption advanced

    A file storage platform encrypts data at rest and in transit. A customer asks whether the provider can read their files. What does the honest answer depend on, and what would change it?

    2 min answer encryptionkey-managementend-to-endthreat-model
  11. Encryption intermediate Multiple choice

    A regulator asks whether customer data is encrypted. The team says yes, disks are encrypted. Is that a sufficient answer?

    2 min answer encryptionthreat-modelcompliance
  12. Encryption beginner Multiple choice

    An attacker obtains the application's database credential from a leaked environment file and runs a SELECT against the customer table. Every volume is encrypted at rest with a managed key service and every connection uses TLS. What does that encryption prevent here?

    3 min answer encryptionat restthreat modelaccess control