1. Supply Chain Security advanced

    A critical CVE is announced in a widely-used library. Walk me through the first four hours.

    2 min answer vulnerabilitysbomresponsepatching
  2. Supply Chain Security advanced

    A data-protection platform depends on hundreds of third-party libraries. What controls meaningfully reduce supply chain risk, and which are theatre?

    2 min answer druvasupply-chainsbomprovenance
  3. Supply Chain Security advanced

    A developer tools company distributes software used inside thousands of organisations. What supply chain controls matter most, and why is this threat model different from a typical SaaS?

    2 min answer supply-chainprovenancesigningbuild-integrity
  4. Supply Chain Security advanced

    An organisation wants to reduce software supply-chain risk. What actually reduces it, in what order, and which popular measures provide less than they appear to?

    3 min answer supply-chainsbomprovenancedependencies
  5. Supply Chain Security advanced

    Codecov disclosed in 2021 that its Bash Uploader script had been modified to exfiltrate continuous integration environment variables, that the modification had been live since late January and that it was found on 1 April by a customer comparing checksums. What made this compromise so productive for the attacker, and what would have limited it?

    3 min answer codecovsupply chaincisecrets
  6. Supply Chain Security advanced Multiple choice

    Your pipeline signs every container image. Is your supply chain secure?

    2 min answer supply-chainprovenanceverification
  7. Threat Modelling intermediate

    A commerce platform threat-models its checkout flow. Which threats are usually missed, and what makes a threat model useful rather than ceremonial?

    2 min answer threat-modellingcheckoutabusestride
  8. Threat Modelling intermediate

    A design review shows a threat model with one trust boundary — internet to application. What boundaries are missing?

    2 min answer threat-modellingboundariesreview
  9. Threat Modelling intermediate

    An insurance platform runs a threat modelling exercise that produces a long list nobody acts on. What went wrong, and what makes threat modelling useful?

    2 min answer ackothreat-modellingprioritisationdesign
  10. Threat Modelling advanced

    Run a threat model on a new payment integration: our service calls a third-party payment provider and receives webhooks. Where are the interesting threats?

    2 min answer threat-modellingstridewebhookspayments
  11. Threat Modelling intermediate

    Threat modelling is widely recommended and rarely practised sustainably. What makes it fail, and what does a version that survives contact with delivery look like?

    2 min answer threat-modellingstridesecurity-reviewprocess
  12. Tokens & JWTs advanced

    A platform uses signed tokens for service-to-service and client authentication. Which properties must be verified on every use, and what goes wrong when they are not?

    2 min answer jwttokensvalidationrevocation