1. Auditability advanced

    A regulated brokerage must prove after the fact who did what, to which account, and on whose authority. What must the architecture provide?

    2 min answer growwauditimmutabilityevidence
  2. Auditability advanced

    A travel platform must be able to answer, months later, who changed a booking and what they saw. What does that require architecturally, and why is a log table insufficient?

    2 min answer auditabilityaudit-logattributionimmutability
  3. Auditability advanced

    Design the audit logging for a system handling financial transactions. What is logged, where does it go, and what makes it hold up?

    2 min answer auditintegrityretentioncompliance
  4. Auditability advanced

    Your audit logs are stored in a platform administered by the same team that has production access. What is the problem?

    2 min answer auditinsider-riskcontrols
  5. Authentication advanced

    A multi-product company must unify authentication across products that each built their own login. What is the migration risk, and how is it sequenced?

    2 min answer authenticationidentitymigrationsso
  6. Authentication advanced Multiple choice

    For service-to-service authentication inside a cluster, would you use mTLS, OAuth client credentials, or both?

    2 min answer mtlsoauthservice-identity
  7. Authentication advanced

    In 2022 the same SMS phishing campaign hit Twilio and Cloudflare within days of each other. Twilio reported unauthorised access to data belonging to around 209 of its roughly 270000 customer accounts. Cloudflare reported that three employees entered credentials on the fake page and that no systems were compromised. What structural difference produced two different outcomes?

    3 min answer twiliocloudflarephishingfido2
  8. Authentication advanced

    You must roll out MFA to 40,000 employees. Security wants hardware keys; the service desk fears the call volume. Design the rollout.

    2 min answer mfaphishing-resistantrolloutrisk
  9. Authorization advanced

    A collaboration platform adds shared channels between separate customer organisations. What data-boundary problems does this create, and how should authorization be modelled?

    3 min answer slackmulti-tenancycross-orgauthorization
  10. Authorization advanced

    A document collaboration product needs sharing with individuals, teams, and inherited folder permissions. Which authorization model?

    2 min answer authorizationrebacrbacmodelling
  11. Authorization advanced

    A multi-tenant platform must guarantee that one customer can never see another's data. Where should that check live, and what makes the guarantee credible?

    2 min answer workosmulti-tenancyisolationauthorization
  12. Authorization advanced

    A workspace product has pages nested arbitrarily deep, with permissions inheritable and overridable at any level, shared with individuals, groups and guests. How should authorization be designed so checks stay fast and correct?

    2 min answer authorizationpermissionsinheritancecaching