1. OAuth 2.0 & OIDC advanced

    A single-page app has used the OAuth implicit flow since 2017 and keeps the access token in localStorage. Security wants authorization code with PKCE behind a backend-for-frontend holding a cookie session. 180000 daily users and 40 third-party embeds must not be logged out. Sequence the migration.

    3 min answer oauthpkcebackend-for-frontendmigration
  2. OAuth 2.0 & OIDC intermediate

    A team proposes the OAuth password grant for your first-party mobile app because "it is our own app". Respond.

    2 min answer oauthmobileauthentication
  3. OWASP Risks intermediate

    A marketplace hosts seller-generated content including descriptions, images and shop pages. Which common web risks are amplified, and what controls apply?

    2 min answer owaspxssuser-contentcsp
  4. OWASP Risks intermediate Multiple choice

    A penetration test reports that every object identifier in your API is a sequential integer and flags insecure direct object reference. Ownership is checked in shared middleware on every route. Three endpoints still returned another user's data: a bulk update that takes an array of identifiers, a nested comment fetch, and a CSV export. Where do you look first?

    3 min answer broken-access-controlidorobject-level-authorizationmiddleware
  5. OWASP Risks advanced

    Broken access control is consistently the top application security risk. Which architectural decisions make it structurally less likely rather than relying on review?

    2 min answer access-controlowaspstructureauthorisation
  6. Privacy Engineering advanced

    A consumer platform with 40 million accounts receives about 600 subject access requests a month. Honouring one means assembling a person's data from 23 services that each own their own store. Estimate what the manual path costs and say what changes the number by an order of magnitude.

    3 min answer dsargdprsubject-indexdata-lineage
  7. Privacy Engineering advanced

    A discovery platform builds personalisation from user behaviour. What privacy-engineering decisions must be made early, and which are expensive to retrofit?

    2 min answer privacydata-minimisationpurpose-limitationdeletion
  8. Privacy Engineering advanced

    Design the mechanism by which a deletion request propagates through a system with a warehouse, a search index, backups and three third-party processors.

    2 min answer privacydeletiongdprpropagation
  9. Privacy Engineering advanced

    Product wants to add "customers who bought this also bought" using purchase history. What does privacy by design require here?

    2 min answer privacypurpose-limitationminimisationgdpr
  10. Secrets Management advanced

    A CI/CD platform runs untrusted code from external contributors and also holds deployment credentials. How should secrets be architected so a malicious pull request cannot exfiltrate them?

    2 min answer secretsci-cduntrusted-codescoping
  11. Secrets Management intermediate

    A payments platform's secrets are in environment variables, set once at deployment. What is wrong, and what should replace it?

    2 min answer razorpaysecretsrotationworkload-identity
  12. Secrets Management intermediate

    A team stores credentials in a secrets manager and considers the problem solved. What is still wrong, and what does a genuinely good secrets posture look like?

    2 min answer secretsrotationworkload-identitycredentials