1. Encryption intermediate Multiple choice

    Your database is encrypted at rest. An attacker obtains valid application credentials. What does the encryption protect against?

    2 min answer encryptionthreat-modelkey-managementat-rest
  2. Identity & Access Management advanced

    A workforce platform holds identity, payroll and device management, and integrates with dozens of downstream systems. What is the central security risk and how is it bounded?

    2 min answer ripplingdeelprivilegeintegrations
  3. Identity & Access Management advanced

    An enterprise platform's permission model has grown to thousands of roles and profiles, and nobody can determine what access a given user actually has. What is the diagnosis and the remediation?

    2 min answer iamrbacabacleast-privilege
  4. Identity & Access Management advanced

    Design the break-glass access mechanism for production. What are the requirements?

    2 min answer accessincidentcontrols
  5. Identity & Access Management intermediate

    Forty developers share one service account to access a partner API because the partner charges per credential. What do you do?

    2 min answer identityattributioncontrols
  6. Security Incident Response advanced

    A blockchain infrastructure provider suspects a compromised credential with access to production. What must the response prioritise, and what capability determines how well it goes?

    2 min answer polygonincident-responsecontainmentforensics
  7. Security Incident Response advanced

    A platform discovers that an attacker has held valid credentials for an unknown period. What does the response require beyond containment, and what determines how well it goes?

    2 min answer incident-responseforensicscredentialsdisclosure
  8. Security Incident Response advanced

    Anomalous access to a customer database is detected. Walk me through the first day, and say what determines whether you can answer the regulator.

    2 min answer incident-responsebreachforensicsnotification
  9. Security Incident Response intermediate

    At 09:00 a customer reports that a report they exported contains another customer's records. You have the on-call. Walk me through your first hour, and tell me what architectural question you would ask on day two.

    3 min answer incident responsemulti-tenancycontainmentforensics
  10. Security Incident Response advanced

    You discover an attacker holds valid credentials in your environment. What are your first three actions and what must already exist for them to be possible?

    2 min answer incident-responsecontainmentforensicscredentials
  11. Key Management advanced

    A communication platform adds end-to-end encryption to multi-party meetings. What are the hard problems, and which are cryptographic versus operational?

    2 min answer key-managemente2eegroup-keystrust
  12. Key Management advanced

    A crypto exchange must hold customer assets while remaining operationally usable. How should key custody, signing, approval and monitoring be architected?

    2 min answer coindcxcustodyhsmsegregation