Security Engineering Cumulative Review
Integrated scenario
A multi-tenant service ships containers through CI/CD to Kubernetes. An external report alleges cross-tenant access. A dependency was recently compromised, a cloud credential appears in logs, and telemetry is incomplete.
Produce:
- asset inventory, data flow, trust boundaries, misuse cases, and risk ranking;
- authentication, session, authorization, cryptographic, and key-lifecycle analysis;
- ASVS verification with safe exploit reproduction and regression;
- host, network, cloud IAM, container, and Kubernetes blast-radius assessment;
- SBOM, signed artifact, provenance, CI permission, admission, and clean-rebuild evidence;
- threat-driven detection, timeline, scope uncertainty, containment, revocation, trusted recovery, and communication;
- architecture corrections, fitness functions, independent-review disposition, and residual-risk decision.
Oral synthesis
Demonstrate one exploit and its repaired regression, trace the running artifact to reviewed source, distinguish evidence from inference in the incident, and defend a go, limit, or stop recommendation.