Exercises
Inventory assets; draw flows; rank scenarios; select password KDF parameters; detect nonce reuse; verify AEAD context; inspect a TLS chain; block replay; harden recovery; test cookie flags; validate OAuth state and PKCE; enforce cross-tenant denial; rotate a workload credential; and exercise break glass.
Required evidence
Submit diagrams, versioned configuration, runnable positive and negative tests, audit events, one rejected design, remediation record, and residual-risk owner. Scanner output without mechanism-level triage does not pass.
Oral defense
Name the attacker and asset, explain the exact control property, demonstrate a denied misuse case, and execute revocation or safe recovery.
Source backbone
Use NIST SP 800-63, OWASP ASVS, relevant RFCs, and Building Secure and Reliable Systems.