Skip to main content

Security Engineering Examination

Time: four hours plus a 25-minute oral defense. Work only in the authorized examination environment.

Part A: Foundations and application

Analyze an identity, session, authorization, and cryptographic design. Find protocol and lifecycle flaws. Map application findings to ASVS and specify general repairs with negative tests.

Part B: Systems and cloud

Given host, packet, IAM, Kubernetes, and audit evidence, reconstruct an attack path, identify blast-radius boundaries, and design containment without destroying necessary evidence.

Part C: Supply chain

Assess source controls, dependency inventory, builder trust, signatures, provenance, CI permissions, promotion, admission, and exceptions. Prove whether a running digest is authorized.

Part D: Detection and response

Triage an ambiguous alert, construct a timeline, state competing hypotheses and gaps, assign incident actions, validate recovery, and propose architecture fitness functions.

Unsupported scanner severity, compliance claims, or certainty lose credit.