Exercises
Inventory dependencies; scope a CVE; compare build inputs; reproduce an artifact; generate SBOM; write VEX; sign and verify; model CI escalation; isolate jobs; author admission policy; rotate identity; detect drift; write disclosure; and time-box an exception.
Required evidence
Submit authorized pipeline configuration, inventory, artifact and provenance identifiers, verification output, injected failure, policy decision, remediation, and residual risk. A green build without trustworthy identity and traceability does not pass.
Oral defense
Trace source to runtime, explain which claim each artifact proves, demonstrate rejection of a substitution, and state the response when trust material is revoked.