1. Security Incident Response advanced

    You discover an attacker holds valid credentials in your environment. What are your first three actions and what must already exist for them to be possible?

    2 min answer incident-responsecontainmentforensicscredentials
  2. Key Management advanced

    A communication platform adds end-to-end encryption to multi-party meetings. What are the hard problems, and which are cryptographic versus operational?

    2 min answer key-managemente2eegroup-keystrust
  3. Key Management advanced

    A crypto exchange must hold customer assets while remaining operationally usable. How should key custody, signing, approval and monitoring be architected?

    2 min answer coindcxcustodyhsmsegregation
  4. Key Management advanced

    A pipeline writes 200 million objects a day and the security review requires per-object encryption with a managed key service. Roughly how many calls to that service does the naive design make, what does it cost, and what changes the answer by two orders of magnitude?

    3 min answer envelope encryptionkmsdata keysthroughput
  5. Key Management advanced

    In a multi-tenant SaaS, would you use one data encryption key for all tenants or one per tenant? Justify.

    2 min answer encryptiontenancyerasure
  6. Network Security beginner

    A security questionnaire asks whether data is encrypted in transit and the team answers yes because the load balancer serves TLS 1.3. What happens if an attacker gets code execution on one host behind that load balancer, and what has the TLS answer actually bought?

    2 min answer tlsterminationmtlslateral-movement
  7. Network Security advanced

    All outbound traffic from a cluster passes through an egress proxy that enforces allowlists and TLS inspection. The proxy does not fail; it gets slow, with p99 rising from 20 ms to 6 s. What happens across the platform over the next ten minutes?

    3 min answer egressproxythread exhaustiontimeouts
  8. Network Security intermediate

    An enterprise wants to segment its network so that a compromised application server cannot reach the database directly. What does segmentation actually buy, and what commonly undermines it?

    2 min answer network-securitysegmentationlateral-movementdefence-in-depth
  9. Network Security intermediate

    Review this design. 12 services and 8 engineers in one cloud region. The proposal adds a service mesh with mutual TLS between every pair of services plus per-service microsegmentation policy plus an external policy decision point consulted on every internal call plus envelope encryption with one data key per record. What would you remove?

    3 min answer over-engineeringservice-meshpolicy-decision-pointenvelope-encryption
  10. Network Security advanced

    You propose egress filtering. Engineering says it will break builds and slow delivery. How do you proceed?

    2 min answer network-securityexfiltrationadoption
  11. OAuth 2.0 & OIDC advanced

    A developer platform issues OAuth tokens to third-party applications. What scope design decisions determine whether the platform can be operated safely long term?

    2 min answer oauthscopesleast-privilegethird-party
  12. OAuth 2.0 & OIDC beginner Multiple choice

    A mobile client sends its OAuth access token as `?access_token=...` because an intermediate proxy strips the Authorization header. Six weeks later the live token values appear in a CDN edge log that 60 engineers can query and in a partner's referrer report. Which change actually closes this?

    3 min answer oauthbearer-tokenloggingtoken-leakage