Security Engineering Examination
Time: four hours plus a 25-minute oral defense. Work only in the authorized examination environment.
Part A: Foundations and application
Analyze an identity, session, authorization, and cryptographic design. Find protocol and lifecycle flaws. Map application findings to ASVS and specify general repairs with negative tests.
Part B: Systems and cloud
Given host, packet, IAM, Kubernetes, and audit evidence, reconstruct an attack path, identify blast-radius boundaries, and design containment without destroying necessary evidence.
Part C: Supply chain
Assess source controls, dependency inventory, builder trust, signatures, provenance, CI permissions, promotion, admission, and exceptions. Prove whether a running digest is authorized.
Part D: Detection and response
Triage an ambiguous alert, construct a timeline, state competing hypotheses and gaps, assign incident actions, validate recovery, and propose architecture fitness functions.
Unsupported scanner severity, compliance claims, or certainty lose credit.