Skip to main content

Quiz

Defend security objectives, threat boundaries, risk, hashes, MACs, KDFs, encryption, signatures, randomness, AEAD, TLS, replay, authentication, sessions, OAuth/OIDC, authorization models, workload identity, rotation, revocation, and break glass.

Required evidence

Submit diagrams, versioned configuration, runnable positive and negative tests, audit events, one rejected design, remediation record, and residual-risk owner. Scanner output without mechanism-level triage does not pass.

Oral defense

Name the attacker and asset, explain the exact control property, demonstrate a denied misuse case, and execute revocation or safe recovery.

Source backbone

Use NIST SP 800-63, OWASP ASVS, relevant RFCs, and Building Secure and Reliable Systems.