---
tags:
- security
- l1
- flashcard-deck
- security-scanning
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Security Scanning](../../../../library/portal/topics.md) | **Domain:** Security
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
security/04ac68682aa2	security	medium	security, supply-chain, incident-response, audit	Give three examples of three potential security threats related to the software supply chain and describe them.	[IEEE](https://ieeexplore.ieee.org/abstract/document/9203862): \n\n  * Sensitive data being exposed or lost.\n    * In a software supply chain, sensitive data may be passed throughout the chain. Security threats involve loss or exposure of this data, such as customer credit card details.\n  * Cloud technology.\n    * Data sharing in the cloud might jeopardize the privacy of the data within the chain.\n  * Third-party vendors.\n    * Third-party vendors’ code solutions might not provide sufficient cybersecurity and risk being a potential subject to data breaches.	projects/knowledge/interview/security/059-give-three-examples-of-three-potential-security-th.txt
security/05d208acc29b	security	easy	security, vulnerability, authentication, secrets	What is CSRF? How to handle CSRF?	Cross-Site Request Forgery (CSRF) is an attack that makes the end user to initiate a unwanted action on the web application in which the user has a authenticated session, the attacker may user an email and force the end user to click on the link and that then execute malicious actions. When an CSRF attack is successful it will compromise the end user data \n\nYou can use OWASP ZAP to analyze a "request", and if it appears that there no protection against cross-site request forgery when the Security Level is set to 0 (the value of csrf-token is SecurityIsDisabled.) One can use data from this request to prepare a CSRF attack by using OWASP ZAP	projects/knowledge/interview/security/046-what-is-csrf-how-to-handle-csrf.txt
security/0d39b450b4d5	security	medium	security, fips, compliance, cryptography	What does it mean to be "FIPS compliant"?	FIPS (Federal Information Processing Standards) compliance means meeting US government cryptographic requirements.\n\nFIPS 140-2/140-3:\n- Standard for cryptographic modules\n- Required for US federal systems\n- Four security levels (1-4)\n\nRequirements:\n- Approved algorithms only (AES, SHA-2, RSA)\n- Validated cryptographic modules\n- Key management procedures\n- Self-tests on startup\n\nWhat it means in practice:\n- Use certified crypto libraries (OpenSSL FIPS module)\n- Disable non-approved algorithms\n- Enable FIPS mode in OS\n- Regular auditing\n\nEnable on Linux:\n- fips=1 kernel parameter\n- /etc/crypto-policies/back-ends/	projects/knowledge/interview/security/074-what-it-means-to-be-fips-compliant.txt
security/118cc703e848	security	easy	security, backdoor, malware	What is a "Backdoor" in information security?	A backdoor is hidden access method bypassing normal authentication.\n\nTypes:\n- Software backdoors: Hidden code in applications\n- Hardware backdoors: Chip-level access\n- Administrative backdoors: Undocumented accounts\n- Protocol backdoors: Intentional weaknesses\n\nHow they get there:\n- Malware installation\n- Developer intentionally added\n- Supply chain compromise\n- Left from development/testing\n- Vulnerability exploitation\n\nExamples:\n- Default credentials\n- Hidden admin accounts\n- Secret URLs/parameters\n- Debug modes in production\n- Hardcoded passwords\n\nDetection:\n- Code review\n- Network monitoring\n- Behavioral analysis\n- Integrity checking\n- Security audits\n\nFamous: SolarWinds backdoor, XZ Utils (CVE-2024-3094)	projects/knowledge/interview/security/106-what-is-a-backdoor-in-information-security.txt
security/12e6eea0204f	security	easy	security, vulnerability	What is an SQL injection? How to manage it?	SQL injection is an attack consists of inserts either a partial or full SQL query through data input from the browser to the web application. When a successful SQL injection happens it will allow the attacker to read sensitive information stored on the database for the web application. \n\nYou can test by using a stored procedure, so the application must be sanitize the user input to get rid of the risk of code injection. If not then the user could enter bad SQL, that will then be executed within the procedure	projects/knowledge/interview/security/040-what-is-an-sql-injection-how-to-manage-it.txt
security/15f6bfd97518	security	medium	security, ssh	How do you secure SSH at scale?	Defense in depth approach:\n\n**Authentication**:\n* Key-only auth (disable password: `PasswordAuthentication no`)\n* No root login (`PermitRootLogin no`)\n* Require specific groups (`AllowGroups sshusers`)\n\n**Architecture**:\n* Bastion/jump hosts - no direct access to internal systems\n* Certificate-based auth for large fleets (SSH CA)\n* Short-lived certificates where possible\n\n**Auditing**:\n* Centralized logging of SSH sessions\n* Session recording for privileged access\n* Alerting on anomalous access patterns\n\n**Enforcement**:\n* Configuration management (Ansible) ensures consistency\n* Compliance scanning detects drift\n* Regular key rotation	projects/knowledge/interview/security/110-how-do-you-secure-ssh-at-scale.txt
security/17b23df108fe	security	medium	security, cryptography, tls	Explain "Forward Secrecy"	Forward Secrecy (Perfect Forward Secrecy) ensures session keys can't be compromised even if long-term keys are.\n\nHow it works:\n- Ephemeral keys generated per session\n- Session key derived from ephemeral exchange\n- Long-term key only authenticates\n- Past sessions safe if private key leaked later\n\nWithout Forward Secrecy:\n- Attacker records encrypted traffic\n- Later obtains server private key\n- Can decrypt all past sessions\n\nWith Forward Secrecy:\n- Each session has unique ephemeral key\n- Key discarded after session\n- Past traffic remains secure\n\nImplementation:\n- Diffie-Hellman Ephemeral (DHE)\n- Elliptic Curve DHE (ECDHE)\n- TLS 1.3 requires forward secrecy\n\nCipher suites: Look for DHE or ECDHE	projects/knowledge/interview/security/103-explain-forward-secrecy.txt
security/1c0bc687090f	security	easy	security, encryption	What is "Diffie-Hellman key exchange" and how does it work?	Have you heard of [The Two General's Problem](https://en.wikipedia.org/wiki/Two_Generals%27_Problem)? The Diffie-Hellman key exchange is a solution to this problem to allow for the secure exchange of cryptographic keys over an encrypted channel.\n\nIt works using public/private key pairs (asymmetric encryption). Two parties that wish to communicate securely over a public channel will each generate a public/private key pair and distribute the public key to the other party (note that public keys are free to be exchanged over a public channel). From here, each party can derive a shared key using a combination of their personal private key and the public key of the other party. This combined key can now be used as a symmetric encryption key for communications.	projects/knowledge/interview/security/051-what-is-diffie-hellman-key-exchange-and-how-does-i.txt
security/1c86149425ff	security	easy	security, encryption	What is a Certificate Authority?	[wikipedia](https://en.wikipedia.org/wiki/Certificate_authority) : A certificate Authority that stores, singns and issues certificates.\n \n A certificate certifies the authenticity of the public key delivered by the website. It prevents [man-in-the-middle](https://en.wikipedia.org/wiki/Man-in-the-middle_attack) attacks by providing a lot of information which identifie the public key.	projects/knowledge/interview/security/013-what-is-a-certificate-authority.txt
security/1ca75c4a3599	security	easy	security, vulnerability	What is SSRF (Server-Side Request Forgery) and why is it dangerous?	SSRF (Server-side request forgery) it's a vulnerability where you can make a server make arbitrary requests to anywhere you want.\n\nRead more about it at [portswigger.net](https://portswigger.net/web-security/ssrf)\n\nRemember: "CIA triad = Confidentiality, Integrity, Availability." Every security control maps to one or more of these.\n\nExample: Encryption = confidentiality, checksums = integrity, redundancy = availability.	projects/knowledge/interview/security/049-what-is-ssrf.txt
security/1e555e2f43f9	security	medium	security, vulnerability, programming	Explain "Format String Vulnerability"	Format string vulnerability occurs when user input is used directly as format string.\n\nVulnerable code:\nprintf(user_input); // WRONG!\n// Instead: printf("%s", user_input);\n\nExploitation:\n- %x: Read stack memory\n- %n: Write to memory\n- %s: Read from arbitrary address\n- Can leak memory or execute code\n\nExample attack:\nInput: "%x %x %x %x"\nOutput: Stack values leaked\n\nPrevention:\n- Never use user input as format string\n- Always use format specifier: printf("%s", input)\n- Compiler warnings: -Wformat-security\n- Static analysis tools\n\nImpact:\n- Information disclosure\n- Denial of service\n- Remote code execution\n\nRemember: "Least privilege = minimum access needed." Don't give root when read-only suffices. Applies to users, services, and API tokens.	projects/knowledge/interview/security/093-explain-format-string-vulnerability.txt
security/2038a6b2eb84	security	medium	security, network-security	How Microsegmentation is applied?	There are different ways to apply Microsegmentation:\n\n- Cloud Native: Using cloud embedded capabilities such as security groups, firewalls, etc.\n- Agent: Agents running on the different endpoints (instances, services, etc.)\n- Network: Modify network devices and their configuration to create microsegmentation	projects/knowledge/interview/security/070-how-microsegmentation-is-applied.txt
security/25df8cd5db05	security	medium	security, encryption	Explain Symmetrical encryption	A symmetric encryption is any technique where a key is used to both encrypt and decrypt the data/entire communication.\n\nExample: nmap -sS -p 1-1000 10.0.0.1 does a SYN scan of the first 1000 ports.\n\nRemember: "nmap = network mapper." SYN scan (-sS) is stealthy; connect scan (-sT) completes the handshake.	projects/knowledge/interview/security/029-explain-symmetrical-encryption.txt
security/2618bebb641e	security	medium	security, oauth, authentication, authorization	What is OAuth and how does it enable delegated authorization?	OAuth 2.0 is an authorization framework for delegated access.\n\nKey concept:\n- Grants limited access without sharing credentials\n- "Login with Google/Facebook/GitHub"\n- Third-party apps access resources on your behalf\n\nRoles:\n- Resource Owner: User\n- Client: Application requesting access\n- Authorization Server: Issues tokens\n- Resource Server: Hosts protected resources\n\nFlow (Authorization Code):\n1. App redirects to auth server\n2. User logs in and consents\n3. Auth server redirects with code\n4. App exchanges code for token\n5. App uses token to access API\n\nToken types:\n- Access token: Short-lived API access\n- Refresh token: Get new access tokens\n\nCommon use: SSO, API access, third-party integrations\n\nRemember: "CVE = Common Vulnerabilities and Exposures." Format: CVE-YEAR-NUMBER. Example: CVE-2021-44228 is Log4Shell.\n\nFun fact: MITRE maintains the CVE database. NVD (NIST) adds severity scores.	projects/knowledge/interview/security/078-explain-oauth.txt
security/26f980f7d448	security	hard	security, containers, docker, kubernetes, linux	Why is "root inside container" still dangerous despite container isolation?	Containers share the kernel with the host - root in container has paths to root on host.\n\nThe shared kernel problem:\n- Containers are NOT VMs\n- Same kernel handles syscalls for container and host\n- Kernel vulnerability = container escape\n- Root in container can exploit kernel bugs\n\nSpecific risks:\n\n1. Capabilities\n   - Root has capabilities even in container\n   - CAP_SYS_ADMIN = near-complete control\n   - Misconfigured: --privileged = actual root	projects/knowledge/interview/security/111-root-in-container-still-root.txt
security/28c7528b67bb	security	medium	security, encryption	Explain Asymmetrical encryption	Asymmetric encryption is any technique where there are two different keys that are used for encryption and decryption, these keys are known as public key and private key.	projects/knowledge/interview/security/030-explain-asymmetrical-encryption.txt
security/2ba3350e4a09	security	medium	security, cyber-security	HIDS vs NIDS and which one is better and why?	**HIDS** is host intrusion detection system and **NIDS** is network intrusion detection system. Both the systems work on the similar lines. It’s just that the placement in different. **HIDS** is placed on each host whereas **NIDS** is placed in the network. For an enterprise, **NIDS** is preferred as **HIDS** is difficult to manage, plus it consumes processing power of the host as well.\n\nRemember: "Defense in depth = layers." Network, host, app, data — compromise one layer, others still protect.\n\nExample: Firewall + WAF + input validation + encryption = four layers.	projects/knowledge/interview/security/003-hids-vs-nids-and-which-one-is-better-and-why.txt
security/33be995826c8	security	easy	security, encryption	What is DNS Spoofing? How to prevent it?	DNS spoofing occurs when a particular DNS server’s records of “spoofed” or altered maliciously to redirect traffic to the attacker. This redirection of traffic allows the attacker to spread malware, steal data, etc.\n\n**Prevention**\n- Use encrypted data transfer protocols - Using end-to-end encryption via SSL/TLS will help decrease the chance that a website / its visitors are compromised by DNS spoofing.\n- Use DNSSEC - DNSSEC, or Domain Name System Security Extensions, uses digitally signed DNS records to help determine data authenticity.\n- Implement DNS spoofing detection mechanisms - it’s important to implement DNS spoofing detection software. Products such as XArp help product against ARP cache poisoning by inspecting the data that comes through before transmitting it.	projects/knowledge/interview/security/043-what-is-dns-spoofing-how-to-prevent-it.txt
security/3ba6a1eaaed6	security	medium	security, encryption	How is hashing different from encryption?	Encrypted data can be decrypted to its original value. Hashed data cannot be reversed to view the original data - hashing is a one-way function.	projects/knowledge/interview/security/036-how-is-hashing-different-from-encryption.txt
security/3eea42ac197c	security	medium	security, access-control, audit	Explain the flow of using cookies	1. User enters credentials\n2. The server verifies the credentials -> a sessions is created and stored in the database\n3. A cookie with the session ID is set in the browser of that user\n4. On every request, the session ID is verified against the database\n5. The session is destroyed (both on client-side and server-side) when the user logs out\n\nRemember: "Patch Tuesday = Microsoft's monthly update cycle (2nd Tuesday)." Linux distros have their own cadences — subscribe to security mailing lists.\n\nGotcha: Unpatched systems are the #1 attack vector. Automate patching where possible.	projects/knowledge/interview/security/026-explain-the-flow-of-using-cookies.txt
security/3f36a3759726	security	hard	security, cyber-security	10 quick points about web server hardening.	Example:\n\n- if machine is a new install, protect it from hostile network traffic, until the operating system is installed and hardened\n- create a separate partition with the `nodev`, `nosuid`, and `noexec` options set for `/tmp`\n- create separate partitions for `/var`, `/var/log`, `/var/log/audit`, and `/home`\n- enable randomized virtual memory region placement\n- remove legacy services (e.g.	projects/knowledge/interview/security/009-10-quick-points-about-web-server-hardening.txt
security/42ab8b34e211	security	medium	security, vulnerability, incident-response, supply-chain	How can you make sure that you use trustworthy packages for your project?	You can’t. You will always be exposed to security risk once you start using open source or vendor packages. The goal is to minimize the risk in order to avoid security breaches. This could be done by:\n\n  * Regularly update the project's dependencies to apply latest bug fixes and vulnerability clean-ups.\n  * However, unless you trust the author, do not update your dependencies instantly, since package updates recently have been a common target by hackers.\n  * Check for changes of the file content in previous versions.	projects/knowledge/interview/security/066-how-can-you-make-sure-that-you-use-trustworthy-pac.txt
security/42fa80176fb9	security	medium	security, audit	Explain "Web Cache Deception Attach"	Web Cache Deception Attack tricks a cache server into storing sensitive, user-specific pages by appending a cacheable extension to the URL. \nExample: attacker shares `https://example.com/account/settings/logo.png` — the CDN caches the account page because of the .png extension. Mitigation: configure caches to respect Cache-Control headers and validate Content-Type before caching.	projects/knowledge/interview/security/056-explain-web-cache-deception-attach.txt
security/430275b614a8	security	medium	security, cyber-security	What is a WAF and what are its types?	**WAF** stands for web application firewall. It is used to protect the application by filtering legitimate traffic from malicious traffic. **WAF** can be either a box type or cloud based.\n\nRemember: "2FA = something you know + something you have." Password + TOTP app, or password + hardware key.	projects/knowledge/interview/security/005-what-is-a-waf-and-what-are-its-types.txt
security/48d11062e057	security	easy	security, supply-chain, vulnerability	What is a package manager?	[Baudry et al.](https://arxiv.org/pdf/2001.07808.pdf): "A tool that allows you to easily download, add and thus reuse programming libraries in your project." E.g. npm or yarn.\n\nRemember: "RBAC = Role-Based Access Control." Users get roles, roles get permissions. Simpler than per-user ACLs at scale.\n\nExample: In K8s, a ClusterRole "viewer" grants get/list/watch on all resources.	projects/knowledge/interview/security/060-what-is-a-package-manager.txt
security/48e38cf5cd21	security	easy	security, scanning, reconnaissance	What is port scanning? When is it used?	Port scanning probes systems to find open ports and services.\n\nPurpose:\n- Security assessment (find open services)\n- Penetration testing\n- Network inventory\n- Malicious reconnaissance\n\nTypes:\n- TCP Connect: Full connection\n- SYN scan: Half-open (stealthier)\n- UDP scan: UDP services\n- Version detection: Identify service versions\n\nTools:\n- nmap: Industry standard\n- masscan: Very fast\n- netcat: Simple probing\n\nnmap examples:\n- nmap -sS target: SYN scan\n- nmap -sV target: Version detection\n- nmap -p 1-1000 target: Specific ports\n- nmap -A target: Aggressive scan\n\nLegal note: Only scan systems you're authorized to test.\n\nDetection: IDS/IPS, firewall logs\n\nRemember: "WAF = Web Application Firewall." It inspects HTTP traffic for attacks (SQLi, XSS, etc.) at layer 7.\n\nExample: AWS WAF, Cloudflare WAF, ModSecurity (open source).	projects/knowledge/interview/security/087-what-is-port-scanning-when-is-it-used.txt
security/4a07817f1e7b	security	medium	security, audit	What can you tell me about Stuxnet?	Stuxnet is a computer worm that was originally aimed at Iran’s nuclear facilities and has since mutated and spread to other industrial and energy-producing facilities. The original Stuxnet malware attack targeted the programmable logic controllers (PLCs) used to automate machine processes. It generated a flurry of media attention after it was discovered in 2010 because it was the first known virus to be capable of crippling hardware and because it appeared to have been created by the U.S. National Security Agency, the CIA, and Israeli intelligence.	projects/knowledge/interview/security/044-what-can-you-tell-me-about-stuxnet.txt
security/4a47256b7225	security	medium	security, authentication, risk	Explain Risk-based authentication	Risk-based authentication adjusts security based on context and risk signals.\n\nRisk factors evaluated:\n- Location (unusual country?)\n- Device (new device?)\n- Time (unusual hours?)\n- Behavior (different patterns?)\n- IP reputation\n- Failed attempts history\n\nResponses based on risk:\n- Low risk: Normal login\n- Medium risk: Additional verification (MFA)\n- High risk: Block and alert\n\nExamples:\n- Login from new country → require MFA\n- Unusual time + new device → additional questions\n- Multiple failures → temporary lockout\n\nBenefits:\n- Better user experience (less friction normally)\n- Stronger security when needed\n- Adaptive to threats\n\nUsed by: Banks, Google, Microsoft, etc.	projects/knowledge/interview/security/077-explain-risk-based-authentication.txt
security/4b2b53db7130	security	hard	security, cyber-security	What is a false positive and false negative in case of IDS?	When the device generated an alert for an intrusion which has actually not happened: this is **false positive** and if the device has not generated any alert and the intrusion has actually happened, this is the case of a **false negative**.	projects/knowledge/interview/security/008-what-is-a-false-positive-and-false-negative-in-cas.txt
security/4e37444fadb0	security	medium	security, encryption, authorization	Does Kerberos make use of symmetric encryption, asymmetric encryption, both, or neither?	Symmetric Encryption - Kerberos uses exclusively symmetric encryption with pre-shared keys for transmitting encrypted information and authorizing users.\n\nExample: Lynis audit: lynis audit system scans for hardening issues.\n\nRemember: "CIS Benchmarks = industry-standard hardening checklists." Available for every major OS and cloud platform.	projects/knowledge/interview/security/020-does-kerberos-make-use-of-symmetric-encryption-asy.txt
security/4e651d85757e	security	medium	security, networking, isolation	What is air-gapped network or air-gapped environment?	Air-gapped network is physically isolated from other networks.\n\nCharacteristics:\n- No internet connection\n- No network links to other systems\n- Complete physical isolation\n- Data transfer via removable media only\n\nUse cases:\n- Military/classified systems\n- Critical infrastructure (power grids)\n- Financial transaction systems\n- Nuclear facilities\n- Secure development environments\n\nChallenges:\n- Data transfer is cumbersome\n- Updates require manual process\n- Still vulnerable to:\n  - Insider threats\n  - Infected removable media (Stuxnet)\n  - Side-channel attacks\n\nSecurity measures:\n- Strict media policies\n- Media scanning stations\n- Physical security\n- Personnel screening\n\nNot foolproof: Stuxnet crossed air gaps via USB.\n\nRemember: "Fail2ban watches logs, bans IPs." It parses log files for failed auth attempts and adds firewall rules.\n\nExample: fail2ban-client status sshd shows banned IPs.	projects/knowledge/interview/security/100-what-is-air-gapped-network-or-air-gapped-environme.txt
security/536b9ec29419	security	medium	security, authorization, access-control	Explain RBAC (Role-based Access Control)	Access control based on user roles (i.e., a collection of access authorizations a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within an organization. A given role may apply to a single individual or to several individuals.\n\n- RBAC mapped to job function, assumes that a person will take on different roles, overtime, within an organization and different responsibilities in relation to IT systems.	projects/knowledge/interview/security/014-explain-rbac-role-based-access-control.txt
security/555f51365f9a	security	medium	security, cyber-security	What is compliance in IT and why does it matter?	Abiding by a set of standards set by a government/Independent party/organisation, e.g. an industry which stores, processes or transmits Payment related information needs to be complied with PCI DSS (Payment card Industry Data Security Standard). Other compliance examples can be an organisation complying with its own policies.	projects/knowledge/interview/security/004-what-is-compliance.txt
security/55ec0781ea2f	security	medium	security, authentication	True or False? Cookie-based authentication is stateful	True. Cookie-based authentication session must be kept on both server and client-side.\n\nRemember: "OWASP Top 10 = most critical web app security risks." Updated periodically. #1 is usually injection or broken access control.	projects/knowledge/interview/security/025-true-or-false-cookie-based-authentication-is-state.txt
security/573d44f76eaf	security	medium	security, authentication, authorization	Explain Authentication and Authorization	Authentication is the process of identifying whether a service or a person is who they claim to be.\nAuthorization is the process of identifying what level of access the service or the person have (after authentication was done)\n\nRemember: "SQL injection = untrusted input in SQL queries." Prevention: parameterized queries (prepared statements), never string concatenation.	projects/knowledge/interview/security/015-explain-authentication-and-authorization.txt
security/59c74930ee57	security	easy	security, certificates, pki, tls	What is Certification Authority?	A CA (Certificate Authority) issues and manages digital certificates.\n\nRole:\n- Verifies identity of certificate requesters\n- Signs certificates with CA's private key\n- Maintains certificate revocation lists (CRL)\n- Trusted by browsers/systems (root CA)\n\nCertificate chain:\n- Root CA → Intermediate CA → End certificate\n- Root CAs pre-installed in browsers/OS\n- Intermediate CAs sign server certificates\n\nTypes:\n- Public CAs: DigiCert, Let's Encrypt, Comodo\n- Private CAs: Internal enterprise use\n- Self-signed: No CA (not trusted publicly)\n\nCertificate contains:\n- Subject (who it's for)\n- Issuer (CA)\n- Public key\n- Validity period\n- Signature\n\nRemember: "Security headers = free defense layer." Key headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options.	projects/knowledge/interview/security/082-what-is-certification-authority.txt
security/5a54984f45ff	security	medium	security, vulnerability, incident-response	What are CVE and CVSS, and how are they used in vulnerability management?	[Red Hat](https://www.redhat.com/en/topics/security/what-is-cve#how-does-it-work) : "When someone refers to a CVE (Common Vulnerabilities and Exposures), they mean a security flaw that's been assigned a CVE ID number. They don’t include technical data, or information about risks, impacts, and fixes." So CVE is just identified by an ID written with 8 digits. The CVE ID have the following format:  CVE prefix + Year + Arbitrary Digits.\n Anyone can submit a vulnerability, [Exploit Database](https://www.exploit-db.com/submit) explains how it works to submit.\n  \nThen CVSS stands for Common Vulnerability Scoring System, it attempts to assign severity scores to vulnerabilities, allowing to ordonnance and prioritize responses and resources according to threat.	projects/knowledge/interview/security/042-explain-cve-and-cvss.txt
security/5b9e1d81a198	security	medium	security, supply-chain, vulnerability	Describe bloated dependencies.	[Baudry et al.](https://arxiv.org/pdf/2001.07808.pdf): \nAn application usually has different dependencies. Typically, not all of them are required for building and running the application. Bloated dependencies is the concept of including the unnecessary dependencies for building and running your application.	projects/knowledge/interview/security/062-describe-bloated-dependencies.txt
security/5d918a3dc0dd	security	medium	security, encryption, cryptography	What is the difference between asynchronous and synchronous encryption?	Terms usually refer to symmetric vs asymmetric encryption:\n\nSymmetric (Synchronous):\n- Same key encrypts and decrypts\n- Fast, efficient\n- Key distribution challenge\n- Algorithms: AES, ChaCha20\n- Use: Bulk data encryption\n\nAsymmetric:\n- Public/private key pair\n- Public encrypts, private decrypts\n- Slower but solves key distribution\n- Algorithms: RSA, ECDSA, Ed25519\n- Use: Key exchange, signatures\n\nHybrid approach (common):\n- Asymmetric to exchange session key\n- Symmetric for bulk data\n- Example: TLS handshake\n\nSigning (asymmetric):\n- Private key signs\n- Public key verifies\n- Proves authenticity\n\nRemember: "IDS detects, IPS prevents." IDS alerts on suspicious traffic; IPS actively blocks it.\n\nExample: Snort and Suricata can run in either IDS or IPS mode.	projects/knowledge/interview/security/088-what-is-the-difference-between-asynchronous-and-sy.txt
security/5f946a206695	security	medium	security, encryption, authentication	True or False? The private key can be mathematically computed from a public key	False. The private key cannot be derived from the public key — that's the fundamental security property of asymmetric cryptography. If this were possible, all public-key encryption would be broken.	projects/knowledge/interview/security/033-true-or-false-the-private-key-can-be-mathematicall.txt
security/61257fdf79a7	security	easy	security, incident-response, access-control	What is Microsegmentation?	- Security method\n- Managing network access between endpoints (processes, devices, instances)\n- A method in which security policies are applied to limit traffic\n  - based on concepts such as "Zero Trust" and "Least Privileged"\n- The result of Microsegmentation should be:\n  - Reduced attack ability\n  - Better breach containment	projects/knowledge/interview/security/068-what-is-microsegmentation.txt
security/618a7606c0ba	security	medium	security, vulnerability	Explain MAC flooding attack	MAC address flooding attack (CAM table flooding attack) is a type of network attack where an attacker connected to a switch port floods the switch interface with very large number of Ethernet frames with different fake source MAC address.	projects/knowledge/interview/security/050-explain-mac-flooding-attack.txt
security/62e4060c2912	security	easy	security, supply-chain, hardening	What is a build tool?	[Baudry et al.](https://arxiv.org/pdf/2001.07808.pdf): "A tool that fetches the packages (dependencies) that are required to compile, test and deploy your application."\n\nRemember: "Container image scanning = CVE checking for containers." Scan in CI before deploy.\n\nExample: trivy image nginx:latest scans for known vulnerabilities.	projects/knowledge/interview/security/061-what-is-a-build-tool.txt
security/63d4d2ea11af	security	medium	security, architecture, design	What are some examples of security architecture requirements?	Security architecture covers multiple domains:\n\nNetwork security:\n- Segmentation (VLANs, firewalls)\n- DMZ for public services\n- Zero trust architecture\n- Encrypted transit (TLS everywhere)\n\nIdentity & Access:\n- Centralized authentication (SSO)\n- Multi-factor authentication\n- Role-based access control\n- Privileged access management\n\nData protection:\n- Encryption at rest and in transit\n- Data classification\n- DLP (Data Loss Prevention)\n- Backup and recovery\n\nApplication security:\n- Secure SDLC\n- WAF protection\n- Input validation\n- Security testing (SAST/DAST)\n\nMonitoring:\n- SIEM implementation\n- Log aggregation\n- Intrusion detection\n- Incident response plan\n\nCompliance: SOC2, HIPAA, PCI-DSS, GDPR\n\nRemember: "Rootless containers = no root daemon." Podman runs rootless by default; Docker requires configuration.	projects/knowledge/interview/security/099-what-are-some-examples-of-security-architecture-re.txt
security/646698d4852f	security	easy	security, ddos, networking	What is port flooding?	Port flooding overwhelms network ports with traffic to cause denial of service.\n\nTypes:\n- SYN flood: Half-open TCP connections\n- UDP flood: Random UDP packets\n- ICMP flood: Ping flood\n\nSYN flood details:\n- Attacker sends many SYN packets\n- Server allocates resources for each\n- Never completes handshake\n- Connection table exhausted\n- Legitimate users can't connect\n\nDefense:\n- SYN cookies\n- Rate limiting\n- Connection timeouts\n- Increase backlog queue\n- Firewall filtering\n- DDoS protection services\n\nDetection:\n- High number of SYN_RECV connections\n- netstat -an | grep SYN_RECV\n- Monitoring alerts\n\nPart of larger DDoS attack strategy.	projects/knowledge/interview/security/102-what-is-port-flooding.txt
security/6627e3dad48e	security	easy	security, cryptography, nonce	What is a nonce and how is it used in cryptography?	Nonce (Number used ONCE) is a random/unique value used once in cryptographic operations.\n\nPurpose:\n- Prevent replay attacks\n- Ensure uniqueness of operations\n- Add randomness to encryption\n\nUses:\n- TLS handshake (random bytes)\n- API authentication (prevent request replay)\n- OAuth state parameter\n- CSRF tokens\n- Proof of work (blockchain mining)\n\nProperties:\n- Should be unique\n- Often random\n- Sometimes sequential counter\n- Never reused with same key\n\nExample (API):\n1. Server provides nonce\n2. Client includes nonce in signed request\n3. Server verifies and invalidates nonce\n4. Replay attempt fails (nonce already used)	projects/knowledge/interview/security/101-what-is-nonce.txt
security/68a277d1b12f	security	hard	security, linux	How do you debug SELinux denials properly?	Never blindly generate policies. Understand the denial first.\n\n**Step-by-step**:\n```bash\n# 1. Find the denial\nausearch -m avc -ts recent\n\n# 2. Understand why\naudit2why < /var/log/audit/audit.log\n\n# 3. Check context\nls -Z /path/to/file\nps -eZ | grep process\n```\n\n**Common fixes**:\n* Wrong file context: `restorecon -Rv /path`\n* Need new context: `semanage fcontext -a -t type_t '/path(/.*)?'`\n* Need boolean: `setsebool -P httpd_can_network_connect on`\n\n**Only after understanding**, if custom policy needed:\n```bash\naudit2allow -M mypolicy < /var/log/audit/audit.log\nsemodule -i mypolicy.pp\n```	projects/knowledge/interview/security/108-how-do-you-debug-selinux-denials-properly.txt
security/68cbc12c02a1	security	medium	security, authentication, encryption, vulnerability	Explain how the Kerberos authentication protocol works as a SSO solution	Kerberos works as a SSO solution by only requiring the user to sign in using their credentials once within a specific validity time window. Kerberos authentication grants the user a Ticket Granting Ticket (TGT) from a trusted authentication server which can then be used to request service tickets for accessing various services and resources. By passing around this encrypted TGT instead of credentials, the user does not need to sign-in multiple times for each resource that has been integrated with Kerberos.	projects/knowledge/interview/security/019-explain-how-the-kerberos-authentication-protocol-w.txt
security/69950aacef2d	security	medium	security, authentication, jwt, tokens	Explain Token-based authentication	Token-based auth uses tokens instead of sending credentials repeatedly.\n\nHow it works:\n1. User authenticates (username/password)\n2. Server issues token (JWT, opaque token)\n3. Client stores token\n4. Token sent with each request\n5. Server validates token\n\nJWT (JSON Web Token):\n- Header: Algorithm, type\n- Payload: Claims (user ID, expiry, roles)\n- Signature: Validates integrity\n- Self-contained, stateless\n\nBenefits:\n- No session storage on server\n- Scalable (stateless)\n- Works across domains\n- Mobile-friendly\n\nSecurity considerations:\n- Token expiry (short-lived)\n- Secure storage (httpOnly cookies)\n- HTTPS required\n- Refresh token rotation	projects/knowledge/interview/security/076-explain-token-based-authentication.txt
security/6c2e9d536014	security	medium	security, cookies, authentication, sessions	What are cookies? Explain cookie-based authentication.	Cookies are small data pieces stored by browser, sent with requests.\n\nCookie-based auth flow:\n1. User submits credentials\n2. Server creates session, stores server-side\n3. Server sends session ID in cookie\n4. Browser sends cookie with every request\n5. Server looks up session\n\nCookie attributes:\n- HttpOnly: JavaScript can't access\n- Secure: HTTPS only\n- SameSite: CSRF protection\n- Domain/Path: Scope\n- Expires/Max-Age: Lifetime\n\nSession storage:\n- Server-side: Database, Redis\n- Stateful (unlike JWT)\n\nSecurity:\n- HttpOnly prevents XSS token theft\n- SameSite=Strict prevents CSRF\n- Secure ensures encryption\n- Short expiry limits damage	projects/knowledge/interview/security/080-what-are-cookies-explain-cookie-based-authenticati.txt
security/6fa356548646	security	medium	security, cyber-security	What is XSS, how will you mitigate it?	**Cross Site Scripting** is a JavaScript vulnerability in the web applications. The easiest way to explain this is a case when a user enters a script in the client side input fields and that input gets processed without getting validated. This leads to untrusted data getting saved and executed on the client side.\n\nCountermeasures of XSS are input validation, implementing a CSP (Content security policy) and other.	projects/knowledge/interview/security/002-what-is-xss-how-will-you-mitigate-it.txt
security/6fcc088984e4	security	medium	security, authentication	How to mitigate password attacks?	* Strong password policy\n  * Do not reuse passwords\n  * ReCaptcha\n  * Training personnel against Social Engineering\n  * Risk Based Authentication\n  * Rate limiting\n  * MFA	projects/knowledge/interview/security/023-how-to-mitigate-password-attacks.txt
security/70234e236ff1	security	medium	security, vlan, networking	Do using VLANs contribute to network security?	VLANs provide network segmentation but are not a security boundary.\n\nSecurity benefits:\n- Logical separation of traffic\n- Reduced broadcast domain\n- Limit lateral movement\n- Easier access control between VLANs\n\nLimitations:\n- VLAN hopping attacks possible\n- Misconfiguration can expose traffic\n- Layer 2 only, need firewalls for filtering\n- Not encryption\n\nVLAN hopping attacks:\n- Switch spoofing: Pretend to be trunk\n- Double tagging: Nested VLAN tags\n\nBest practices:\n- Disable DTP (Dynamic Trunking Protocol)\n- Use dedicated VLAN for management\n- Prune VLANs on trunks\n- Don't use VLAN 1\n- Firewall between VLANs\n\nVLANs are one layer, not complete security.\n\nRemember: "Audit logs = forensic evidence." Log who did what, when, from where. Immutable storage prevents tampering.	projects/knowledge/interview/security/098-do-using-vlans-contribute-to-network-security.txt
security/7047e5d9ec5f	security	medium	security, linux, networking	iptables vs nftables - what matters?	nftables is the successor to iptables with significant improvements:\n\n**nftables advantages**:\n* Faster rule processing (single evaluation)\n* Unified framework (no separate ip6tables, arptables)\n* Atomic rule updates (no packet loss during reload)\n* Better syntax, easier to read\n* Sets and maps for efficient matching\n\n**Conceptually similar**: Both use chains, rules, hooks. Knowledge transfers.\n\n**Practical reality**:\n* RHEL 8+/Debian 10+ default to nftables\n* `iptables` command often wraps nftables backend\n* Legacy scripts still work via compatibility layer\n\n**Migration**: `iptables-translate` converts rules to nftables syntax.	projects/knowledge/interview/security/109-iptables-vs-nftables-what-matters.txt
security/72b3d12fb514	security	medium	security, tcp, udp, networking, vulnerabilities	What TCP and UDP vulnerabilities are you familiar with?	Protocol-level vulnerabilities in TCP/UDP:\n\nTCP vulnerabilities:\n- SYN Flood: Exhaust connection table\n- TCP Reset Attack: Spoofed RST packets\n- Session Hijacking: Predict sequence numbers\n- TCP Timestamp Attack: Leak system info\n\nUDP vulnerabilities:\n- UDP Flood: Volumetric DoS\n- DNS Amplification: Abuse DNS for DDoS\n- NTP Amplification: Abuse NTP monlist\n- SSDP Reflection: Abuse UPnP\n\nMitigations:\n- SYN cookies (SYN flood)\n- Rate limiting\n- Ingress filtering (BCP38)\n- Disable unnecessary UDP services\n- Response rate limiting\n\nNetwork level:\n- BGP hijacking awareness\n- TCP/IP stack hardening\n- Proper firewall rules	projects/knowledge/interview/security/097-what-tcp-and-udp-vulnerabilities-are-you-familiar-.txt
security/72f9f8efc412	security	medium	security, networking, dmz, architecture	What is a DMZ (demilitarized zone) in network security?	DMZ (Demilitarized Zone) is a network segment between internal and external networks.\n\nPurpose:\n- Hosts public-facing services\n- Adds security layer\n- Isolates internal network\n\nArchitecture:\n- Firewall 1: Internet ↔ DMZ\n- Firewall 2: DMZ ↔ Internal\n- Double-layer protection\n\nDMZ typically contains:\n- Web servers\n- Mail servers\n- DNS servers\n- Reverse proxies\n- VPN endpoints\n\nRules:\n- Internet → DMZ: Limited ports\n- DMZ → Internal: Very restricted\n- Internal → DMZ: As needed\n\nBenefits:\n- Breach in DMZ doesn't expose internal\n- Defense in depth\n- Compliance requirement	projects/knowledge/interview/security/094-explain-dmz.txt
security/75540b5ecd21	security	easy	security, authentication, encryption	What is password salting? What attack does it help to deter?	Password salting is the processing of prepending or appending a series of characters to a user's password before hashing this new combined value. This value should be different for every single user but the same salt should be applied to the same user password every time it is validated.\n\n This ensures that users that have the same password will still have very different hash values stored in the password database. This process specifically helps deter rainbow table attacks since a new rainbow table would need to be computed for every single user in the database.	projects/knowledge/interview/security/024-what-is-password-salting-what-attack-does-it-help-.txt
security/75b27198a5dd	security	medium	security, encryption	True or False? The symmetrical encryption is making use of public and private keys where the private key is used to decrypt the data encrypted with a public key	False. Symmetric encryption uses the same shared key for both encryption and decryption (e.g., AES-256). The description of public/private key pairs fits asymmetric encryption (e.g., RSA, ECDSA). In practice, TLS uses asymmetric encryption for the initial key exchange, then switches to faster symmetric encryption for the session data.	projects/knowledge/interview/security/032-true-or-false-the-symmetrical-encryption-is-making.txt
security/76d8f40e84f9	security	easy	security, arp, networking, attacks	What is ARP Poisoning?	ARP poisoning (ARP spoofing) manipulates Address Resolution Protocol to intercept traffic.\n\nHow ARP works normally:\n- Maps IP addresses to MAC addresses\n- Broadcast "Who has 192.168.1.1?"\n- Response "I'm at aa:bb:cc:dd:ee:ff"\n\nARP poisoning attack:\n1. Attacker sends fake ARP replies\n2. Victim's ARP cache poisoned\n3. Traffic meant for gateway goes to attacker\n4. Enables MITM attack\n\nAttack tool: arpspoof, ettercap\n\nDefense:\n- Static ARP entries (not scalable)\n- Dynamic ARP Inspection (switches)\n- ARP monitoring (arpwatch)\n- Encrypt traffic (HTTPS, VPN)\n- 802.1X authentication\n\nLimited to local network (same broadcast domain).\n\nRemember: "Zero trust = never trust, always verify." No implicit trust based on network location.	projects/knowledge/interview/security/090-what-is-arp-poisoning.txt
security/78a5630e95d6	security	medium	security, vulnerability, supply-chain, audit	Briefly describe what a software supply chain is.	A company’s software supply chain consists of any third party or open source component which could be used to compromise the final product. Such component is usually an API provided by an actor. For instance Twilio who offers mobile communication APIs to their customers. \n\n[WhiteSource](https://www.whitesourcesoftware.com/resources/blog/software-supply-chain-security-the-basics-and-four-critical-best-practices/): "Enterprise software projects increasingly depend on third-party and open source components.	projects/knowledge/interview/security/057-briefly-describe-what-a-software-supply-chain-is.txt
security/7f9b3366a457	security	medium	security, linux	SELinux - why keep it enabled?	SELinux provides Mandatory Access Control (MAC) that catches classes of exploits that discretionary permissions (DAC) never will.\n\n**Why it matters**:\n* Limits damage from compromised processes - even root can be constrained\n* Defense in depth - if app has vulnerability, SELinux limits lateral movement\n* Catches misconfigurations that DAC would allow\n* Required for many compliance standards\n\n**Common objection**: "It breaks things" - usually means something is misconfigured, not that SELinux is wrong.\n\n**Proper approach**: Debug denials, fix policies, don't disable. An attacker who compromises your app is betting you turned it off.	projects/knowledge/interview/security/107-selinux-why-keep-it-enabled.txt
security/81ad6e5ecc03	security	medium	security, encryption	True or False? In the case of SSH, asymmetrical encryption is not used to the entire SSH session	True. In SSH, asymmetric encryption is used only during the initial key exchange to securely establish a shared session key. After that, all data is encrypted with faster symmetric encryption (typically AES-256). The asymmetric step ensures the symmetric key is shared securely without being intercepted. This hybrid approach balances security with performance.	projects/knowledge/interview/security/034-true-or-false-in-the-case-of-ssh-asymmetrical-encr.txt
security/82d1570db50b	security	easy	security, network-security, vulnerability	What is Cache Poisoned Denial of Service?	CPDoS or Cache Poisoned Denial of Service. It poisons the CDN cache. By manipulating certain header requests, the attacker forces the origin server to return a Bad Request error which is stored in the CDN’s cache. Thus, every request that comes after the attack will get an error page.\n\nRemember: "SIEM = Security Information and Event Management." It aggregates logs, correlates events, and alerts on threats.	projects/knowledge/interview/security/052-what-is-cache-poisoned-denial-of-service.txt
security/83e26fb674ed	security	medium	security, authorization, encryption, vulnerability	What is a checksum and how is it used to verify data integrity?	[Fred Cohen (permission needed)](https://reader.elsevier.com/reader/sd/pii/0167404887900319?token=D5339ABC064AD9A2B50B74D8CE890B0E22A302A0BC461A50078D407BEA01052737DC6AAEF95A854E72A73B6D0C67E260&originRegion=eu-west-1&originCreation=20220502180611): Checksum is a way to verify the integrity of information in systems with no built-in protection. In other words, it provides a way of validating that the content of a file or a package / library is intact. This is useful since attacks or errors may occur during transmission of files.	projects/knowledge/interview/security/067-explain-checksum.txt
security/846aac7af8c8	security	medium	security, vulnerability, supply-chain	What're some benefits of a software supply chain?	[Increment](https://increment.com/apis/apis-supply-chain-software/): Resource-saving. Using and paying for existing solutions to resource-heavy problems saves time as well as money. Hence resulting in efficient, cheap and greater opportunities to develop and deploy software products for consumers.	projects/knowledge/interview/security/058-whatre-some-benefits-of-a-software-supply-chain.txt
security/88997d0ff362	security	easy	security, cyber-security	What is a Security Misconfiguration?	**Security misconfiguration** is a vulnerability when a device/application/network is configured in a way which can be exploited by an attacker to take advantage of it. This can be as simple as leaving the default username/password unchanged or too simple for device accounts etc.\n\nRemember: "Supply chain attacks target dependencies, not your code." SolarWinds, Codecov, and npm package hijacks are examples.	projects/knowledge/interview/security/001-what-is-a-security-misconfiguration.txt
security/889da37dda04	security	medium	security, supply-chain, vulnerability	Explain a few cons of bloated dependencies.	[Baudry et al.](https://arxiv.org/pdf/2001.07808.pdf): \n\n  * Challenging to manage.\n  * Decreases performance of the application.\n  * Risk for malicious code that a threathening actor can take advantage of.	projects/knowledge/interview/security/063-explain-a-few-cons-of-bloated-dependencies.txt
security/955d041246b7	security	hard	security, apt, threats	Explain "Advanced persistent threat (APT)"	APT is a sophisticated, long-term cyber attack by well-resourced adversaries.\n\nCharacteristics:\n- Advanced: Custom tools, zero-days\n- Persistent: Months to years presence\n- Threat: Targeted at specific org/data\n\nTypical APT phases:\n1. Reconnaissance: Research target\n2. Initial compromise: Spear phishing, watering hole\n3. Establish foothold: Backdoors, persistence\n4. Lateral movement: Spread through network\n5. Data collection: Find valuable data\n6. Exfiltration: Steal data covertly\n7. Maintain presence: Stay hidden\n\nAttackers:\n- Nation-states (APT28, APT29, APT41)\n- State-sponsored groups\n- Well-funded criminal organizations\n\nDefense:\n- Defense in depth\n- Threat intelligence\n- Network monitoring\n- Endpoint detection\n- User training\n- Incident response plan\n\nRemember: "DAST = Dynamic Application Security Testing." It tests running apps by sending malicious requests (black-box testing).\n\nExample: OWASP ZAP is a popular free DAST tool.	projects/knowledge/interview/security/105-explain-advanced-persistent-threat-apt.txt
security/96ed18b4ff71	security	medium	security, vulnerability, incident-response	What are ephemeral environments in the context of Microsegmentation?	- These are short-lived resources like containers or serverless functions that start and stop quickly.\n- Because they don’t last long, they need security rules that can change just as fast.\n- Microsegmentation helps by giving each one exactly the network access it needs — nothing more.	projects/knowledge/interview/security/071-what-are-ephemeral-environments-in-the-context-of-.txt
security/97073638f260	security	easy	security, ddos, networking	What is DDoS attack? How do you deal with it?	DDoS (Distributed Denial of Service) overwhelms systems with traffic.\n\nTypes:\n- Volumetric: Flood bandwidth (UDP flood)\n- Protocol: Exploit protocol weaknesses (SYN flood)\n- Application: Target application layer (HTTP flood)\n\nDefense strategies:\n1. CDN/DDoS protection services\n   - Cloudflare, AWS Shield, Akamai\n   - Absorb and filter traffic\n\n2. Rate limiting\n   - Limit requests per IP\n   - Connection limits\n\n3. Traffic analysis\n   - Identify attack patterns\n   - Block suspicious sources\n\n4. Anycast\n   - Distribute traffic globally\n   - No single point to overwhelm\n\n5. Over-provisioning\n   - More capacity than needed\n   - Absorb spikes\n\n6. Response plan\n   - Documented procedures\n   - Contact ISP/hosting provider	projects/knowledge/interview/security/086-what-is-ddos-attack-how-do-you-deal-with-it.txt
security/9bdfa8ad7d9e	security	easy	security, ssl, tls, cryptography	What is the difference, if any, between SSL and TLS?	TLS is the successor to SSL; they are different protocol versions.\n\nHistory:\n- SSL 1.0: Never released\n- SSL 2.0: 1995, deprecated\n- SSL 3.0: 1996, deprecated (POODLE)\n- TLS 1.0: 1999, deprecated\n- TLS 1.1: 2006, deprecated\n- TLS 1.2: 2008, current standard\n- TLS 1.3: 2018, latest\n\nKey differences:\n- TLS has stronger cipher suites\n- TLS has improved handshake\n- TLS 1.3 is faster and more secure\n- SSL protocols have known vulnerabilities\n\nTerminology:\n- "SSL" often used colloquially for TLS\n- "SSL certificate" actually works with TLS\n- OpenSSL library supports both\n\nCurrent recommendation:\n- Use TLS 1.2 or 1.3 only\n- Disable all SSL versions\n- Disable TLS 1.0 and 1.1	projects/knowledge/interview/security/104-what-is-the-difference-if-any-between-ssl-and-tls.txt
security/9bf595d93acc	security	hard	security, cyber-security	What is the difference between policies, processes and guidelines?	As **security policy** defines the security objectives and the security framework of an organisation. A **process** is a detailed step by step how to document that specifies the exact action which will be necessary to implement important security mechanism. **Guidelines** are recommendations which can be customized and used in the creation of procedures.	projects/knowledge/interview/security/007-what-is-the-difference-between-policies-processes-.txt
security/a186def8dccf	security	medium	security, authentication, vulnerability	What password attacks are you familiar with?	Common password attacks: Dictionary (tries common words and passwords from leaked databases), Brute Force (tries every possible combination), Password Spraying (tries a few common passwords against many accounts to avoid lockouts), and Social Engineering variants: Phishing (fake emails/sites), Vishing (voice calls), Whaling (targeting executives). Mitigations: MFA, account lockout policies, and password managers.	projects/knowledge/interview/security/022-what-password-attacks-are-you-familiar-with.txt
security/a40cc0050b03	security	medium	security, vulnerability, compliance, audit	What solutions are there for managing project dependencies?	[Npm.js documentation](https://docs.npmjs.com/cli/v8/commands/npm-prune): Use clean-up commands that are usually provided by the package manager authors. For instance, npm prune will remove any extraneous package. Another command is npm audit which will scan your repository and report any vulnerable dependencies found.\n\nRemember: "Penetration testing = authorized attack simulation." Red team attacks, blue team defends, purple team collaborates.	projects/knowledge/interview/security/064-what-solutions-are-there-for-managing-project-depe.txt
security/ab699d6ca277	security	easy	security, vulnerability, incident-response, secrets	What is XSS (Cross-Site Scripting) and how is it prevented?	Cross Site Scripting (XSS) is an type of a attack when the attacker inserts browser executable code within a HTTP response. Now the injected attack is not stored in the web application, it will only affect the users who open the maliciously crafted link or third-party web page. A successful attack allows the attacker to access any cookies, session tokens, or other sensitive information retained by the browser and used with that site	projects/knowledge/interview/security/039-what-is-xss.txt
security/ab781d779a6b	security	hard	security, cyber-security	What is CSRF (Cross-Site Request Forgery) and how is it prevented?	**Cross Site Request Forgery** is a web application vulnerability in which the server does not check whether the request came from a trusted client or not. The request is just processed directly. It can be further followed by the ways to detect this, examples and countermeasures.	projects/knowledge/interview/security/006-what-is-csrf.txt
security/ae03633f1f39	security	medium	security, incident-response	What the "Zero Trust" concept means? How Organizations deal with it?	[Codefresh definition](https://codefresh.io/security-testing/codefresh-runner-overview): "Zero trust is a security concept that is centered around the idea that organizations should never trust anyone or anything that does not originate from their domains. Organizations seeking zero trust automatically assume that any external services it commissions have security breaches and may leak sensitive information"	projects/knowledge/interview/security/011-what-the-zero-trust-concept-means-how-organization.txt
security/afb9b46b482b	security	medium	security, encryption, incident-response	How HTTPS is different from HTTP?	The 'S' in HTTPS stands for 'secure'. HTTPS uses TLS to provide encryption of HTTP requests and responses, as well as providing verifaction by digitally signing requests and responses. As a result, HTTPS is far more secure than HTTP and is used by default for most modern websites.	projects/knowledge/interview/security/041-how-https-is-different-from-http.txt
security/b0193bdcfcc5	security	easy	security, authentication, vulnerability, access-control	Explain what is Single Sign-On	SSO (Single Sign-on), is a method of access control that enables a user to log in once and gain access to the resources of multiple software systems without being prompted to log in again.	projects/knowledge/interview/security/018-explain-what-is-single-sign-on.txt
security/b92ce9f63d11	security	medium	security, firewall, networking	What types of firewalls are there?	Firewalls filter traffic at different layers:\n\nPacket Filter (Stateless):\n- Filters by IP, port, protocol\n- Each packet independent\n- Fast but limited\n- Example: Basic iptables rules\n\nStateful Firewall:\n- Tracks connection state\n- Allows return traffic automatically\n- More intelligent filtering\n- Example: iptables with conntrack\n\nApplication Layer (WAF):\n- Inspects application content\n- HTTP/HTTPS aware\n- Blocks SQL injection, XSS\n- Example: ModSecurity, AWS WAF\n\nNext-Gen Firewall (NGFW):\n- Deep packet inspection\n- Application awareness\n- IPS integration\n- User identity aware\n- Example: Palo Alto, Fortinet\n\nCloud/Host-based:\n- Security groups (AWS)\n- Network policies (Kubernetes)\n- Host firewall (firewalld, ufw)\n\nRemember: "Threat modeling = structured 'what could go wrong?'" STRIDE: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.	projects/knowledge/interview/security/085-what-types-of-firewalls-are-there.txt
security/ba2137763195	security	easy	security, authentication, authorization	Give an example of basic authentication process	A user uses the browser to authenticate to some server. It does so by using the authorization field which is constructed from the username and the password combined with a single colon. The result string is encoded using a certain character set which is compatible with US-ASCII. The authorization method + a space is prepended to the encoded string.	projects/knowledge/interview/security/016-give-an-example-of-basic-authentication-process.txt
security/ba4779c69309	security	medium	security, network-security, access-control	What challenges arise when scaling Microsegmentation?	- As more systems get added, managing all the rules becomes harder.\n- It’s tough to keep security rules consistent when everything’s changing all the time.\n- You also have to be careful not to slow things down while keeping everything secure.	projects/knowledge/interview/security/073-what-challenges-arise-when-scaling-microsegmentati.txt
security/ba50a2a476dc	security	easy	security, vulnerability, supply-chain	What is a threatening actor and how can this actor take advantage of open source or third party vendor's packages/libraries?	[Wikipedia](https://en.wikipedia.org/wiki/Threat_actor): A threatening actor is one or more people who target technical artifacts such as software, networks and/or devices with the purpose of harming it.\n\n[Aquasec](https://www.aquasec.com/cloud-native-academy/devsecops/supply-chain-security/): An attacking actor may identify, target and inject malicious software in a vulnerable part of an open source package or a third party vendor’s code. The consumer of this code may consequently and unknowingly deploy the malicious code throughout their pipelines, thus infecting their own projects. An example of this happening is the hack of [SolarWinds](https://www.npr.org/2021/04/16/985439655/a-worst-nightmare-cyberattack-the-untold-story-of-the-solarwinds-hack).	projects/knowledge/interview/security/065-what-is-a-threatening-actor-and-how-can-this-actor.txt
security/ba81f7699628	security	medium	security, network-security, access-control	How does Microsegmentation help prevent lateral movement?	- It sets tight rules for how services or systems can talk to each other.\n- If one system gets hacked, the attacker can’t easily move to others.\n- By dividing systems into smaller zones, it makes the whole network harder to break into.	projects/knowledge/interview/security/072-how-does-microsegmentation-help-prevent-lateral-mo.txt
security/bd77c4e7e4a5	security	medium	security, authentication, secrets	What are the three primary factors of authentication? Give three examples of each	Something you have\n- Smart card\n- Physical authentication device\n- Software token\n\nSomething you know\n- Password\n- PIN\n- Passphrase\n\nSomething you are\n- Fingerprint\n- Iris or retina scan\n- Gait analysis	projects/knowledge/interview/security/017-what-are-the-three-primary-factors-of-authenticati.txt
security/bf1a74e73133	security	medium	security, vulnerability, incident-response	Explain HTTP Header Injection vulnerability	HTTP Header Injection vulnerabilities occur when user input is insecurely included within server responses headers. If an attacker can inject newline characters into the header, then they can inject new HTTP headers and also, by injecting an empty line, break out of the headers into the message body and write arbitrary content into the application's response.\n\nRemember: "Secrets scanning in CI catches leaked credentials." Tools: gitleaks, truffleHog, detect-secrets.\n\nExample: gitleaks detect --source . scans the git history for secrets patterns.	projects/knowledge/interview/security/047-explain-http-header-injection-vulnerability.txt
security/bf875e8eedbb	security	easy	security, vulnerability, hardening	Explain what is Buffer Overflow	A buffer overflow (or buffer overrun) occurs when the volume of data exceeds the storage capacity of the memory buffer. As a result, the program attempting to write the data to the buffer overwrites adjacent memory locations.	projects/knowledge/interview/security/048-explain-what-is-buffer-overflow.txt
security/c247fbee4e4d	security	easy	security, encryption, authentication	What is "Key Exchange" (or "key establishment") in cryptography?	[Wikipedia](https://en.wikipedia.org/wiki/Key_exchange): "Key exchange (also key establishment) is a method in cryptography by which cryptographic keys are exchanged between two parties, allowing use of a cryptographic algorithm."	projects/knowledge/interview/security/031-what-is-key-exchange-or-key-establishment-in-crypt.txt
security/c6aba2de2cb0	security	easy	security, encryption	What is SNI (Server Name Indication)?	[Wikipedia](https://en.wikipedia.org/wiki/Server_Name_Indication): "an extension to the Transport Layer Security (TLS) computer networking protocol by which a client indicates which hostname it is attempting to connect to at the start of the handshaking process"\n\nRemember: "SSH hardening: disable password auth, use keys, change default port, use fail2ban."	projects/knowledge/interview/security/054-what-is-sni-server-name-indication.txt
security/c724d8e951af	security	easy	security, authentication	What authentication methods are there?	Authentication verifies identity through several methods:\n\nSomething you know:\n- Password\n- PIN\n- Security questions\n\nSomething you have:\n- Hardware token (YubiKey)\n- Smart card\n- Phone (SMS, authenticator app)\n- Certificate\n\nSomething you are:\n- Fingerprint\n- Face recognition\n- Retina scan\n- Voice\n\nMulti-factor (MFA):\n- Combines two or more methods\n- Example: Password + TOTP\n- Significantly more secure\n\nFor systems:\n- SSH keys\n- Kerberos tickets\n- OAuth tokens\n- Certificates (mTLS)	projects/knowledge/interview/security/075-what-authentication-methods-are-there.txt
security/cbf46ab2fab2	security	easy	security, vulnerability, risk	Explain the following: vulnerability, exploit, risk	Three related but distinct security concepts:\n\nVulnerability:\n- A weakness in a system\n- Could be exploited\n- Example: SQL injection flaw, unpatched software\n- CVEs catalog known vulnerabilities\n\nExploit:\n- Code/technique that uses vulnerability\n- Actually leverages the weakness\n- Example: Exploit code for CVE-2021-44228\n- Proof of concept or weaponized\n\nRisk:\n- Probability × Impact\n- Likelihood of exploitation AND damage\n- Factors: Exposure, exploitability, asset value\n- Risk = Threat × Vulnerability × Asset Value\n\nRelationship:\n- Vulnerability exists\n- Exploit activates vulnerability\n- Risk quantifies potential damage\n\nRisk management: Identify vulnerabilities, assess risk, prioritize fixes.	projects/knowledge/interview/security/081-explain-the-following-vulnerability-exploits-risk-.txt
security/cdf2ffc1e62b	security	medium	security, encryption	What's SSL termination (or SSL offloading)?	SSL termination is the process of decrypting encrypted traffic. The advantage in SSL termination is that the server doesn't have to perform it, we can use SSL termination to reduce the load on the server, speed up some processes, and allow the server to focus on its core functionality (e.g. deliver content)	projects/knowledge/interview/security/053-whats-ssl-termination-or-ssl-offloading.txt
security/ce0ccbfac7b1	security	easy	security, encryption	What is hashing and how is it used in security and data integrity?	Hashing is a mathematical function for mapping data of arbitrary sizes to fixed-size values. This function produces a "digest" of the data that can be used for verifying that the data has not been modified (amongst other uses)	projects/knowledge/interview/security/035-what-is-hashing.txt
security/ce7540fa0a8f	security	easy	security, learning, resources	What security sources are you using to keep updated?	Multiple sources for security awareness:\n\nVulnerability databases:\n- NVD (National Vulnerability Database)\n- CVE (Common Vulnerabilities and Exposures)\n- Vendor security bulletins\n\nNews and blogs:\n- Krebs on Security\n- The Hacker News\n- Ars Technica Security\n- Schneier on Security\n\nMailing lists:\n- oss-security\n- Full Disclosure\n- Vendor security lists (Ubuntu, Red Hat)\n\nSocial media:\n- Twitter security researchers\n- Reddit r/netsec\n\nFeeds:\n- US-CERT alerts\n- SANS Internet Storm Center\n\nTools:\n- Feedly for aggregation\n- RSS feeds\n\nActive participation:\n- Security conferences (DEF CON, Black Hat)\n- CTF competitions\n- Bug bounty programs\n\nRemember: "Network segmentation = blast radius control." VLANs, security groups, and network policies limit lateral movement.	projects/knowledge/interview/security/096-what-security-sources-are-you-using-to-keep-update.txt
security/d6dc9def59b0	security	medium	security, git, repositories	Describe how do you secure public repositories	Protecting code in public repositories:\n\nPrevent secrets exposure:\n- Never commit credentials\n- Use .gitignore for sensitive files\n- Pre-commit hooks (git-secrets)\n- Scan history for secrets (trufflehog)\n- Environment variables for secrets\n\nBranch protection:\n- Require PR reviews\n- Protected branches (no force push)\n- Status checks before merge\n- Signed commits\n\nAccess control:\n- Minimal write access\n- Review collaborators regularly\n- Use teams with appropriate permissions\n\nCode security:\n- Dependency scanning (Dependabot)\n- SAST tools (CodeQL)\n- License compliance\n- Security policy (SECURITY.md)\n\nMonitoring:\n- Enable security alerts\n- Watch for forks\n- Audit log review	projects/knowledge/interview/security/091-describe-how-do-you-secure-public-repositories.txt
security/d7e4dbd07b62	security	medium	security, tls, encryption, networking	What is TLS (Transport Layer Security) and how does it secure communication?	TLS (Transport Layer Security) encrypts network communication.\n\nPurpose:\n- Confidentiality (encryption)\n- Integrity (tampering detection)\n- Authentication (certificates)\n\nTLS handshake:\n1. Client Hello (supported ciphers, TLS version)\n2. Server Hello (chosen cipher, certificate)\n3. Key exchange (establish shared secret)\n4. Encrypted communication begins\n\nVersions:\n- TLS 1.0, 1.1: Deprecated\n- TLS 1.2: Current standard\n- TLS 1.3: Latest, faster handshake\n\nComponents:\n- Certificates: Identity verification\n- Cipher suites: Encryption algorithms\n- Key exchange: ECDHE, DHE\n\nUse cases:\n- HTTPS (web)\n- SMTPS, IMAPS (email)\n- Database connections\n- API communication	projects/knowledge/interview/security/095-explain-tls.txt
security/da465b4bfdac	security	medium	security, encryption	How hashes are part of SSH?	Hashes used in SSH to verify the authenticity of messages and to verify that nothing tampered with the data received.	projects/knowledge/interview/security/037-how-hashes-are-part-of-ssh.txt
security/dc06607e81cc	security	easy	security, supply-chain, audit	What is DevSecOps? What its core principals?	A couple of quotations from chosen companies:\n\n[Snyk](https://snyk.io/series/devsecops): "DevSecOps refers to the integration of security practices into a DevOps software delivery model. Its foundation is a culture where development and operations are enabled through process and tooling to take part in a shared responsibility for delivering secure software."\n\nRemember: Security automation = toil reduction." Automate patching, scanning, compliance checks, and incident response playbooks.	projects/knowledge/interview/security/010-what-is-devsecops-what-its-core-principals.txt
security/dd38217f90a2	security	easy	security, encryption, authentication	What is the role of an SSH key?	[Wikipedia definition](https://en.wikipedia.org/wiki/Secure_Shell) : SSH uses public-key cryptography to authenticate the remote computer and allow it to authenticate the user. Two keys are created, private is stored inside user's computer to decrypt the communication then the public key is stored inside the remoted computer where user want to connect with and it is used to encrypt the communication.	projects/knowledge/interview/security/028-what-is-the-role-of-an-ssh-key.txt
security/de7d9dfc5a7a	security	medium	security, authentication, access-control, audit	Explain MFA (Multi-Factor Authentication)	Multi-Factor Authentication (Also known as 2FA). Allows the user to present two pieces of evidence, credentials, when logging into an account.\n\n- The credentials fall into any of these three categories: something you know (like a password or PIN), something you have (like a smart card), or something you are (like your fingerprint).  Credentials must come from two different categories to enhance security.	projects/knowledge/interview/security/021-explain-mfa-multi-factor-authentication.txt
security/dfc0b3b3cf95	security	medium	security, mitm, networking, attacks	Explain Man-in-the-middle attack	MITM attack intercepts communication between two parties.\n\nHow it works:\n1. Attacker positions between victim and server\n2. Intercepts all traffic\n3. Can read/modify data\n4. Both sides think they're talking directly\n\nAttack vectors:\n- ARP spoofing (LAN)\n- DNS spoofing\n- Rogue WiFi access points\n- SSL stripping\n- BGP hijacking\n\nPrevention:\n- HTTPS (TLS encryption)\n- Certificate pinning\n- HSTS (HTTP Strict Transport Security)\n- VPN on untrusted networks\n- Verify certificate warnings\n\nDetection:\n- Certificate warnings\n- Unexpected redirects\n- Network monitoring\n\nExample: Attacker on coffee shop WiFi intercepts login credentials.	projects/knowledge/interview/security/089-explain-man-in-the-middle-attack.txt
security/e21a6cf67d96	security	medium	security, network-security	Why do we need Microsegmentation solutions? Why using something such as firewalls isn't enough?	- Firewalls focused on north-south traffic. Basically traffic that is outside of the company perimeter\n- Traffic that is considered west-east, internal workflows and communication, is usually left untreated	projects/knowledge/interview/security/069-why-do-we-need-microsegmentation-solutions-why-usi.txt
security/e32f0ec41897	security	medium	security, vulnerability, scanning	How do you identify and manage vulnerabilities?	Systematic approach to vulnerability management:\n\nIdentification:\n- Vulnerability scanners (Nessus, OpenVAS, Qualys)\n- Dependency scanning (Snyk, Dependabot)\n- SAST/DAST for code\n- Penetration testing\n- Bug bounty programs\n\nPrioritization:\n- CVSS score (severity)\n- Exploitability (is exploit public?)\n- Asset criticality\n- Exposure (internal vs public)\n\nRemediation:\n- Patch management\n- Configuration fixes\n- Compensating controls\n- Accept risk (documented)\n\nProcess:\n1. Continuous scanning\n2. Triage and prioritize\n3. Assign to teams\n4. Track remediation\n5. Verify fixes\n6. Report metrics\n\nTools: Jira, ServiceNow for tracking\n\nRemember: "Incident response = Identify, Contain, Eradicate, Recover, Learn." The NIST framework.	projects/knowledge/interview/security/083-how-do-you-identify-and-manage-vulnerabilities.txt
security/e4268add5f6d	security	medium	security, boot, grub, vulnerability	What can you tell me about the BootHole vulnerability?	BootHole (CVE-2020-10713) was a GRUB2 buffer overflow vulnerability.\n\nThe vulnerability:\n- Buffer overflow in GRUB2 config parsing\n- Exploitable via malicious grub.cfg\n- Could bypass Secure Boot\n- Affected most Linux distributions\n\nImpact:\n- Arbitrary code execution in GRUB\n- Persistent malware before OS loads\n- Secure Boot bypass\n- Rootkit installation\n\nMitigation:\n- Update GRUB2 packages\n- Update shim bootloader\n- Revoke vulnerable signatures (dbx)\n- Update firmware\n\nLesson learned:\n- Boot security is complex\n- Secure Boot isn't foolproof\n- Trust chain only as strong as weakest link	projects/knowledge/interview/security/092-what-can-you-tell-me-about-the-boothole-vulnerabil.txt
security/e572640770cf	security	medium	security, encryption, vulnerability	What can you tell me about Spectre?	Spectre is an attack method which allows a hacker to “read over the shoulder” of a program it does not have access to. Using code, the hacker forces the program to pull up its encryption key allowing full access to the program	projects/knowledge/interview/security/045-what-can-you-tell-me-about-spectre.txt
security/e6af6a02c1ad	security	medium	security, secrets, vault	How do you manage sensitive information like passwords?	Use secrets management solutions, never plaintext:\n\nSolutions:\n- HashiCorp Vault: Industry standard\n- AWS Secrets Manager / Parameter Store\n- Azure Key Vault\n- Kubernetes Secrets (basic)\n- Ansible Vault (for configs)\n\nBest practices:\n- Never commit secrets to git\n- Rotate secrets regularly\n- Audit access\n- Encrypt at rest\n- Least privilege access\n- Separate dev/prod secrets\n\nFor applications:\n- Environment variables (okay for some cases)\n- Secrets from Vault at runtime\n- Service accounts with limited scope\n\nTools:\n- git-secrets: Prevent committing secrets\n- detect-secrets: Scan for secrets\n- pre-commit hooks	projects/knowledge/interview/security/079-how-do-you-manage-sensitive-information-like-passw.txt
security/e6b72c0d06fe	security	medium	security, encryption	What benefits SNI introduces?	SNI allows a single server to serve multiple certificates using the same IP and port. \nPractically this means that a single IP can server multiple web services/pages, each using a different certificate.	projects/knowledge/interview/security/055-what-benefits-sni-introduces.txt
security/f9e4acccec1c	security	hard	security, selinux, linux, hardening	Why is disabling SELinux worse than never having it at all?	Disabling SELinux removes security while hiding the misconfigurations it was catching.\n\nThe problem:\n\n1. Loss of audit signal\n   - SELinux denials = visibility into access attempts\n   - Disabled = blind to policy violations\n   - Attackers move freely, no alerts\n\n2. Masked misconfigurations\n   - SELinux enforcing often means "apps configured wrong"\n   - Disabling "fixes" symptoms, not causes\n   - Underlying problems remain, now invisible\n   - Permissions too broad, attack surface increased\n\nRemember: "Encryption at rest = stored data, in transit = network data." Both are required for compliance (PCI-DSS, HIPAA, SOC2).	projects/knowledge/interview/security/110-disabling-selinux-worse.txt
security/fca08695156a	security	medium	security, vulnerability	Are you familiar with "OWASP top 10"?	The OWASP Top 10 is a regularly updated list of the most critical web application security risks. Current top risks include: Broken Access Control, Cryptographic Failures, Injection (SQL/XSS), Insecure Design, Security Misconfiguration, and Server-Side Request Forgery (SSRF). It serves as the baseline standard for web application security testing and developer training.	projects/knowledge/interview/security/038-are-you-familiar-with-owasp-top-10.txt
security/fe77cbc064a3	security	medium	security, access-control, least-privilege	Explain "Privilege Restriction"	Privilege restriction limits access rights to minimum necessary.\n\nPrinciple of Least Privilege:\n- Users get only permissions they need\n- No more, no less\n- Applies to humans and services\n\nImplementation:\n- Role-based access (RBAC)\n- Don't run as root\n- Separate admin accounts\n- Time-limited elevated access\n- Service accounts with minimal scope\n\nLinux examples:\n- sudo instead of root login\n- Drop capabilities in containers\n- SELinux/AppArmor policies\n- File permissions\n\nBenefits:\n- Limits damage from compromise\n- Reduces attack surface\n- Easier auditing\n- Compliance requirement\n\nRelated: Defense in depth, zero trust\n\nRemember: "PKI = Public Key Infrastructure." It manages digital certificates for authentication and encryption.	projects/knowledge/interview/security/084-explain-privilege-restriction.txt
security/0e984a4ac282	security	medium	miscellaneous, control-flow, debugging, encryption	Have you worked with hybrid cloud environments, and how did you integrate them with on-premises data centers?	• Assessment of Workloads: Assess workloads to determine which applications or services are suitable for migration to the cloud and which should remain on-premises. • Selecting Cloud Services: Choose appropriate cloud services and providers based on workload requirements, considering factors like scalability, performance, and cost. • Connectivity Solutions: Implement secure connectivity solutions, such as Virtual Private Networks (VPNs) or dedicated connections, to establish communication between on-premises data centers and the cloud.	
security/24ecbc187d54	security	medium	miscellaneous, control-flow, iam, logging	Discuss a time when you successfully implemented a change that resulted in improved data center efficiency.	In a previous role, we identified inefficiencies in server utilization, leading to increased operational costs and resource wastage. To address this, we implemented a server virtualization initiative. **Steps Taken:* •  • Assessment: Conducted a comprehensive assessment of server utilization, identifying underutilized servers and areas for consolidation. • Virtualization Strategy: Developed a virtualization strategy to migrate workloads to a virtual environment using VMware, optimizing server resources.	
security/2948f4a4a53d	security	medium	miscellaneous, control-flow, iam, networking	Discuss the role of change management in a data center environment.	• Controlled Changes: Change management ensures that all changes to the data center environment, including configurations, hardware, and software, are controlled and documented. • Risk Mitigation: It helps identify potential risks associated with changes, assess their impact, and implement mitigation strategies to prevent disruptions. • Communication: Change management facilitates communication among teams, ensuring that all stakeholders are informed about upcoming changes and their potential impact.	
security/2a2eddb3d043	security	medium	miscellaneous, control-flow, functions, iam	How do you collaborate with other teams, such as network engineers or system administrators?	• Regular Meetings: Schedule regular meetings with cross-functional teams to discuss ongoing projects, share updates, and address challenges collaboratively. • Communication Platforms: Utilize communication platforms such as Slack, Microsoft Teams, or dedicated collaboration tools for real-time communication and file sharing. • Project Planning: Collaborate during the project planning phase to ensure alignment on goals, timelines, and resource requirements.	
security/336f8692a477	security	medium	miscellaneous, control-flow, encryption, networking	What criteria do you consider when choosing between different server or networking equipment vendors?	• Performance and Scalability: Evaluate the performance specifications and scalability of the equipment to ensure it meets current and future demands. • Reliability and Availability: Consider the vendor's track record for reliability and the availability of support services to minimize downtime. • Compatibility: Ensure compatibility with existing infrastructure, protocols, and standards to facilitate seamless integration. • Cost-effectiveness: Analyze the total cost of ownership, including purchase, maintenance, and operational costs, to determine cost-effectiveness.	
security/3a146bc040d1	security	medium	miscellaneous, control-flow, encryption, functions	Explain the concept of server hardening and its importance.	Server hardening is the process of securing a server by reducing its attack surface and strengthening its defenses against potential security threats. It involves implementing security best practices and configurations to minimize vulnerabilities. **Importance:* •  • Mitigating Security Risks: Server hardening helps mitigate security risks by reducing the likelihood of unauthorized access, data breaches, and other security incidents. • Compliance Requirements: It ensures compliance with industry standards and regulations that mandate specific security configurations.	
security/44c4993b17e4	security	medium	miscellaneous, control-flow, iam, networking	How do you create and test a disaster recovery plan for a data center?	Creating and testing a disaster recovery plan involves the following steps: **Risk Assessment:* • Identify potential risks and threats to the data center, such as natural disasters, hardware failures, or cyberattacks. **Critical Asset Identification:* • Determine critical systems, applications, and data that need protection and recovery. **Recovery Objectives:* • Define recovery time objectives (RTO) and recovery point objectives (RPO) for each critical asset.	
security/548db22cfec6	security	medium	miscellaneous, control-flow, iam, logging	Explain the importance of firewalls in a data center environment.	A firewall is a network security device that monitors and controls incoming and outgoing network traffic based on predetermined security rules. **Importance in Data Center:* •  • Access Control: Firewalls control access to and from the data center, allowing only authorized traffic and blocking unauthorized or potentially harmful traffic. • Security Perimeter: Firewalls establish a security perimeter around the data center, acting as a barrier between the internal network and external networks, such as the internet.	
security/7d50839e8c48	security	medium	miscellaneous, control-flow, encryption, iam	What are the security implications of integrating on-premises data centers with cloud services?	• Data Transmission Security: Security implications arise during the transmission of data between on-premises data centers and the cloud. Encryption protocols (TLS/SSL) should be employed to secure data in transit. • Identity and Access Management (IAM): Integrating on-premises systems with cloud services requires a robust IAM strategy to manage user access and permissions across both environments consistently.	
security/900d08f00a53	security	medium	miscellaneous, control-flow, iam, networking	Discuss a situation where you had to communicate technical issues to non-technical stakeholders.	In a previous role, I encountered a critical server outage that affected a key business application. To communicate this technical issue to non-technical stakeholders, I followed these steps: • Clarity in Language: Avoided technical jargon and communicated in clear, simple language to ensure understanding. • Impact Assessment: Clearly outlined the impact on business operations, emphasizing the significance of the issue. • Root Cause Analysis: Provided a brief explanation of the root cause of the outage without delving into overly technical details.	
security/d4a24c365c74	security	medium	miscellaneous, control-flow, iam, networking	Describe a situation where you had to prioritize tasks in a data center environment with limited resources and time.	In a previous role, we faced a situation where multiple critical tasks needed to be addressed urgently, but resources and time were limited. **Steps Taken:* •  • Task Prioritization: Conducted a quick assessment of the tasks based on their impact on business operations and criticality. • Communication: Communicated with stakeholders, including management and end-users, to set expectations regarding task prioritization and potential delays. • Resource Allocation: Assessed the availability of resources, including personnel and equipment, and allocated them based on the priority of tasks.	
security/e647408b0e5c	security	medium	miscellaneous, control-flow, iam, kernel	Discuss your experience with configuration management tools such as Puppet or Chef.	In a previous role, I utilized Puppet for configuration management in a large-scale data center environment. **Key Experiences:* •  • Infrastructure as Code (IaC): Implemented Infrastructure as Code (IaC) principles using Puppet manifests to define and manage infrastructure configurations. • Automated Configuration Deployment: Automated the deployment and configuration of servers, ensuring consistency across the entire infrastructure. • Role-Based Configuration: Organized configurations into role-based modules, allowing for easy management and scalability.	
security/eb69b9e140ea	security	medium	miscellaneous, control-flow, encryption, networking	How do you ensure data integrity and security when decommissioning or repurposing hardware?	• Data Sanitization: Implement data sanitization methods, such as secure erasure or disk wiping, to ensure that sensitive data is irreversibly removed from storage devices. • Encryption Decryption: Encrypt data on storage devices, and only decrypt it when necessary during the decommissioning process. • Secure Disposal: Dispose of hardware securely by following industry best practices, such as physically destroying storage devices or utilizing certified e-waste disposal services.	
security/002	security	easy	security, ssh	Name three SSH hardening basics.	1) Disable root login (PermitRootLogin no). \n2) Use key-based auth and disable password auth. \n3) Use a non-default port or restrict source IPs with AllowUsers/firewall rules. Also: enforce short session timeouts.	training/interactive/knowledge/data/cards/security-ir.tsv
security/003	security	medium	security, ssh, keys	How should SSH keys be managed in production?	Use ssh-agent or a secrets manager — never store unencrypted private keys on disk. Rotate keys periodically. Use ed25519 over RSA. Deploy keys via config management. Revoke departed users' keys immediately.\n\nRemember: "Compliance ≠ security." Being compliant means meeting minimum standards. Being secure means actually defending against threats.	training/interactive/knowledge/data/cards/security-ir.tsv
security/004	security	easy	security, secrets	Why should secrets never be committed to git?	Git history is permanent — even if you delete the file, the secret remains in previous commits. Attackers scan public repos for leaked keys. Use environment variables, vault systems, or .gitignore to prevent exposure.\n\nRemember: "SOC 2 = security audit for service providers." Type I = point-in-time, Type II = over a period (more valuable).	training/interactive/knowledge/data/cards/security-ir.tsv
security/005	security	medium	security, secrets	What should you do immediately after discovering a leaked secret?	1) Rotate/revoke the secret immediately. \n2) Audit access logs for unauthorized use. \n3) Remove from git history (git filter-repo or BFG). \n4) Force-push cleaned history. \n5) Notify affected teams. Speed matters — automated scrapers find leaked keys within minutes.	training/interactive/knowledge/data/cards/security-ir.tsv
security/006	security	easy	security, sudo	What are the risks of granting unrestricted sudo?	Full root access means a compromised account owns the system. Use sudoers to allow only specific commands. Log all sudo usage. Avoid NOPASSWD for privileged commands. Prefer dedicated service accounts over broad sudo.	training/interactive/knowledge/data/cards/security-ir.tsv
security/007	security	medium	security, sudo	How do you audit sudo usage on a Linux system?	Check /var/log/auth.log or /var/log/secure for sudo entries. Use: grep sudo /var/log/auth.log. For centralized auditing, forward sudo logs to a SIEM. Also: sudoreplay if session recording is enabled.	training/interactive/knowledge/data/cards/security-ir.tsv
security/008	security	easy	security, logs	Why is centralized logging important for incident response?	Attackers often tamper with local logs. Centralized logging (syslog, ELK, CloudWatch) preserves evidence, enables correlation across hosts, and provides a timeline. Without it, you may not detect or reconstruct an incident.\n\nRemember: "Backup 3-2-1 rule: 3 copies, 2 media types, 1 offsite." Test restores regularly — untested backups are not backups.	training/interactive/knowledge/data/cards/security-ir.tsv
security/009	security	medium	security, logs	What log sources should you review during a Linux security incident?	/var/log/auth.log (logins, sudo), /var/log/syslog (system events), audit.log (auditd rules), lastlog/wtmp (login history), cron logs, application logs. Also: journalctl for systemd services, and any SIEM alerts.	training/interactive/knowledge/data/cards/security-ir.tsv
security/010	security	medium	security, ioc	What are common indicators of compromise (IOCs) on a Linux host?	Unexpected processes or open ports, modified system binaries (check with rpm -V or debsums), new cron jobs or user accounts, unusual outbound connections, files with recent mtime in /tmp or /dev/shm, unfamiliar SSH authorized_keys entries.\n\nRemember: "mTLS = mutual TLS." Both client and server present certificates. Used in service mesh (Istio, Linkerd) for zero-trust service-to-service auth.	training/interactive/knowledge/data/cards/security-ir.tsv
security/011	security	medium	security, ioc	How do you check for unauthorized cron jobs?	List all user crontabs: for u in $(cut -f1 -d: /etc/passwd); do crontab -l -u $u 2>/dev/null; done. Also check /etc/cron.d/, /etc/cron.daily/, and systemd timers (systemctl list-timers). Compare against a known-good baseline.	training/interactive/knowledge/data/cards/security-ir.tsv
security/012	security	medium	incident-response, containment	What is the difference between containment and eradication?	Containment stops the spread — isolate the host (network ACL, disable account, firewall rule) but keep evidence intact. Eradication removes the threat — delete malware, patch vulnerability, rotate credentials. Contain first, then eradicate.	training/interactive/knowledge/data/cards/security-ir.tsv
security/013	security	medium	incident-response, containment	How do you contain a compromised Linux host without destroying evidence?	1) Isolate network (iptables DROP all or unplug). \n2) Do NOT reboot — volatile memory holds evidence. \n3) Disable compromised accounts. \n4) Snapshot disk/memory if in cloud. \n5) Block known malicious IPs at the firewall. Preserve before you clean.	training/interactive/knowledge/data/cards/security-ir.tsv
security/014	security	hard	incident-response, forensics	Why is it important to avoid rebooting a compromised system during investigation?	RAM contains running processes, network connections, loaded kernel modules, and decrypted data that are lost on reboot. Capture memory (e.g., LiME) and volatile state (ps, netstat, lsof) before any destructive action.	training/interactive/knowledge/data/cards/security-ir.tsv
security/015	security	medium	incident-response, forensics	What is the order of volatility in digital forensics?	Most volatile first: \n1) CPU registers/cache. \n2) RAM. \n3) Network connections and routing tables. \n4) Running processes. \n5) Disk (filesystem). \n6) Remote logs/backups. Collect evidence from most volatile to least to preserve maximum data.	training/interactive/knowledge/data/cards/security-ir.tsv
security/016	security	easy	security, backup	Why must backup restores be tested regularly?	Untested backups may be corrupted, incomplete, or incompatible with current systems. Regular restore drills verify RTO/RPO targets are achievable. An untested backup is not a backup — it is a hope.	training/interactive/knowledge/data/cards/security-ir.tsv
security/017	security	medium	security, backup	How do you validate a restore after a security incident?	1) Restore to an isolated environment. \n2) Verify data integrity (checksums, record counts). \n3) Scan restored data for malware/backdoors. \n4) Check that the backup predates the compromise. \n5) Confirm application functionality before promoting to production.	training/interactive/knowledge/data/cards/security-ir.tsv
security/018	security	medium	incident-response, mistakes	What are common incident responder mistakes?	1) Rebooting the system (destroys volatile evidence). \n2) Running commands on the compromised host that alter state. \n3) Not preserving chain of custody. \n4) Alerting the attacker. \n5) Skipping containment and jumping to eradication. \n6) Failing to rotate all affected credentials.	training/interactive/knowledge/data/cards/security-ir.tsv
security/019	security	medium	security, privilege-escalation	What are common Linux privilege escalation indicators?	1) SUID binaries in unusual locations (find / -perm -4000). \n2) World-writable files in PATH. \n3) Weak sudo rules (sudo -l). \n4) Kernel exploit artifacts in /tmp. \n5) Modified /etc/passwd or /etc/shadow. \n6) Unexpected setcap capabilities on binaries.	training/interactive/knowledge/data/cards/security-ir.tsv
security/020	security	hard	security, privilege-escalation	How do you detect if a kernel exploit was used for privilege escalation?	Check dmesg/syslog for kernel oops or segfaults. Look for exploit source code or compiled binaries in /tmp, /dev/shm. Check kernel version against known CVEs. Compare running kernel modules (lsmod) to baseline. Audit unexpected root processes.	training/interactive/knowledge/data/cards/security-ir.tsv
security/021	security	medium	security, credentials	What patterns indicate credential exposure?	1) Secrets in environment variables visible via /proc/*/environ. \n2) Credentials in shell history files. \n3) Hardcoded passwords in scripts or config files. \n4) API keys in git commits. \n5) Tokens in URL query strings in access logs. \n6) Plaintext passwords in log output.	training/interactive/knowledge/data/cards/security-ir.tsv
security/022	security	medium	security, credentials	After credential exposure, what is the full remediation checklist?	1) Revoke/rotate the exposed credential immediately. \n2) Identify scope of access the credential granted. \n3) Audit logs for unauthorized use of the credential. \n4) Check for lateral movement. \n5) Update all systems using the credential. \n6) Add detection for the old credential in logs.	training/interactive/knowledge/data/cards/security-ir.tsv
security/023	security	easy	incident-response, process	What are the six phases of incident response (NIST)?	1) Preparation. \n2) Identification/Detection. \n3) Containment. \n4) Eradication. \n5) Recovery. \n6) Lessons Learned. Each phase feeds into the next. Post-incident review improves preparation for the next event.	training/interactive/knowledge/data/cards/security-ir.tsv
security/024	security	medium	security, least-privilege	How do you audit for overly permissive IAM or file permissions?	Files: find / -perm -o+w -type f to find world-writable files. IAM (AWS): use Access Analyzer or review policies for Action: * or Resource: *. Locally: audit sudoers, check group memberships, review /etc/passwd for shell access. Automate with periodic scans.\n\nRemember: "Security is everyone's job, not just the security team." DevSecOps = security shifted left into the dev pipeline.	training/interactive/knowledge/data/cards/security-ir.tsv
security/025	security	hard	incident-response, forensics	How do you establish a forensic timeline from Linux logs?	Merge auth.log, syslog, audit.log, and application logs into a single timeline sorted by timestamp. Correlate user logins with file changes (find -newer), process execution (auditd EXECVE records), and network connections. Tools: log2timeline/plaso, or manual grep + sort.	training/interactive/knowledge/data/cards/security-ir.tsv
security/a1b2c3d4	security	easy	sbom,inventory,formats	What is an SBOM and what are the two main formats?	An SBOM (Software Bill of Materials) is a machine-readable inventory of every component in an artifact: libraries, versions, and licenses. The two main formats are SPDX (Linux Foundation standard) and CycloneDX (OWASP standard). SBOMs let you answer "does this image contain log4j?" in seconds rather than days.	training/library/topics/supply-chain-security/primer.md
security/b2c3d4e5	security	medium	slsa,framework,levels	What is SLSA and what do its levels guarantee?	SLSA (Supply-chain Levels for Software Artifacts) is a graduated security framework with Levels 1-3. Higher levels provide stronger guarantees: Level 1 requires build provenance documentation, Level 2 requires a hosted build service, Level 3 requires a hardened build platform with non-falsifiable provenance. Each level increases confidence that an artifact was built from claimed source by a trustworthy system.	training/library/topics/supply-chain-security/primer.md
security/c3d4e5f6	security	medium	cosign,signing,keyless	How does cosign sign container images in keyless mode?	In keyless mode, cosign uses OIDC identity (e.g., GitHub Actions' OIDC token) instead of a static key pair. The CI system proves its identity to Sigstore's Fulcio CA, receives a short-lived signing certificate, signs the image by digest, and records the signature in the Rekor transparency log. Consumers verify using the OIDC issuer and identity constraints.	training/library/topics/supply-chain-security/primer.md
security/d4e5f6a7	security	medium	sigstore,rekor,transparency	What is Rekor and what role does it play in Sigstore?	Rekor is Sigstore's immutable transparency log that records all signing events. When an artifact is signed with cosign, the signature and metadata are logged in Rekor, creating a tamper-evident audit trail. Anyone can search Rekor to verify when and by whom an artifact was signed, providing non-repudiation even for keyless signatures.	training/library/topics/supply-chain-security/primer.md
security/e5f6a7b8	security	hard	in-toto,attestation,provenance	What is an in-toto attestation and how does it differ from a simple signature?	An in-toto attestation binds a subject (artifact digest) to a structured predicate (build provenance, vuln scan results, SBOM). While a simple signature only proves who signed, an attestation also proves how the artifact was produced, what tests passed, and what components it contains. Policy engines like Kyverno can enforce rules based on attestation predicates.	training/library/topics/supply-chain-security/primer.md
security/f6a7b8c9	security	hard	dependency-confusion,attack,supply-chain	What is a dependency confusion attack and how do you prevent it?	Dependency confusion exploits package managers that check public registries before private ones. An attacker publishes a higher-versioned package with the same name as an internal package to a public registry (npm, PyPI). The build system then pulls the malicious public version. Prevent it by configuring scoped registries, pinning exact versions, using lockfiles, and setting up registry priority rules.	training/library/topics/supply-chain-security/primer.md
security/a7b8c9da	security	medium	kyverno,admission,policy	How does Kyverno enforce container image signature verification in Kubernetes?	Kyverno is a Kubernetes admission controller that evaluates policies before pods are created. A ClusterPolicy with verifyImages rules checks that images matching specified patterns (e.g., "ghcr.io/org/*") have valid cosign signatures from authorized identities. If an unsigned or improperly signed image is deployed, the admission webhook denies the pod creation.	training/library/topics/supply-chain-security/street_ops.md
security/b8c9daeb	security	easy	grype,scanning,vulnerabilities	How do you scan a container image for vulnerabilities using grype?	Run "grype ghcr.io/org/myapp:v1.2.3" to scan an image against CVE databases. Use "--fail-on high" to fail CI on high/critical vulnerabilities. Output JSON with "-o json" and filter for critical issues with jq. You can also scan from an SBOM: "grype sbom:./sbom.spdx.json" for faster repeated scans.	training/library/topics/supply-chain-security/street_ops.md
security/c9daebfc	security	medium	sbom,syft,generation	How do you generate and attach an SBOM to a container image?	Generate an SBOM with syft: "syft ghcr.io/org/myapp:v1.2.3 -o spdx-json > sbom.spdx.json" (or -o cyclonedx-json for CycloneDX). Attach it as an OCI artifact with "cosign attach sbom --sbom sbom.spdx.json ghcr.io/org/myapp:v1.2.3". Consumers can then verify the SBOM attestation with "cosign verify-attestation --type spdxjson".	training/library/topics/supply-chain-security/street_ops.md
security/daebfcad	security	hard	slsa,provenance,github-actions	How do you generate SLSA Level 3 provenance in GitHub Actions?	Use the slsa-framework/slsa-github-generator reusable workflow. In your release workflow, build and push the image, capture its digest, then call the generator workflow with the image and digest as inputs. The workflow requires id-token: write permission for keyless signing. Verify locally with "cosign verify-attestation --type slsaprovenance".	training/library/topics/supply-chain-security/street_ops.md
security/ebfcadbe	security	easy	cosign,verify,command	What cosign command verifies a signed container image and what flags constrain trust?	Use "cosign verify" with --certificate-identity-regexp (constrains which identity signed it, e.g., a GitHub Actions workflow path) and --certificate-oidc-issuer (constrains which OIDC provider issued the token, e.g., https://token.actions.githubusercontent.com). Both flags together establish a chain of trust: the image was signed by a specific CI pipeline.	training/library/topics/supply-chain-security/primer.md
security/fcadbecf	security	hard	opa,image-verification,policy	How can OPA Gatekeeper be used for image verification as an alternative to Kyverno?	OPA Gatekeeper uses ConstraintTemplates with Rego policy language to define image verification rules. While Kyverno has built-in verifyImages, Gatekeeper requires custom Rego logic or external data (e.g., calling a verification webhook). Kyverno is simpler for image signing use cases, but Gatekeeper offers more flexible general-purpose policy expression.	training/library/topics/supply-chain-security/primer.md
security/a1c2d3e4	security	easy	vault,basics,purpose	What is HashiCorp Vault and what are its core use cases?	Vault is the industry standard for secrets management, providing centralized storage and access control for secrets. Core use cases include static secret storage (KV engine), dynamic credential generation (database, cloud IAM), encryption-as-a-service (transit engine), PKI certificate management, and audit logging of all secret access.	training/library/topics/hashicorp-vault/primer.md
security/b2d3e4f5	security	medium	vault,seal,unseal	What does it mean for Vault to be sealed vs unsealed, and how does unsealing work?	When Vault starts, it is sealed -- it knows where encrypted data is stored but cannot decrypt it. Unsealing requires providing a threshold of key shares (Shamir's Secret Sharing, e.g., 3 of 5 shares). Once enough shares are provided, Vault reconstructs the master key, decrypts the encryption key, and becomes operational. Auto-unseal via cloud KMS is the production alternative.	training/library/topics/hashicorp-vault/primer.md
security/c3e4f5a6	security	medium	vault,approle,auth	What is AppRole auth and how do applications authenticate to Vault?	AppRole is Vault's machine-oriented auth method. An application authenticates using a role_id (like a username, relatively static) and a secret_id (like a password, often single-use and short-lived). The secret_id is typically delivered via a trusted broker or CI system. On successful auth, Vault returns a token with policies attached.	training/library/topics/hashicorp-vault/primer.md
security/d4f5a6b7	security	medium	vault,kv,versions	What is the difference between KV v1 and KV v2 secrets engines?	KV v1 is a simple key-value store with no versioning -- writes overwrite the previous value permanently. KV v2 adds versioning: every write creates a new version, and you can read, compare, or rollback to any previous version. KV v2 also supports check-and-set (CAS) to prevent accidental overwrites and metadata like creation time and deletion time.	training/library/topics/hashicorp-vault/primer.md
security/e5a6b7c8	security	hard	vault,transit,encryption	What is the transit secrets engine and when would you use it?	The transit engine provides encryption-as-a-service: applications send plaintext to Vault's API and receive ciphertext back (or vice versa) without ever handling encryption keys directly. Use it for application-level encryption (encrypting database fields, files) when you want centralized key management, key rotation, and audit logging without embedding crypto libraries in every app.	training/library/topics/hashicorp-vault/primer.md
security/f5b7c8d9	security	hard	vault,dynamic,credentials	How do dynamic credentials work in Vault and why are they more secure than static secrets?	When an application requests dynamic credentials (e.g., a database login), Vault creates a unique, short-lived credential on demand with a TTL lease. Each application instance gets its own credential. When the lease expires, Vault automatically revokes the credential. This eliminates shared passwords, makes credential rotation automatic, and provides per-client attribution in audit logs.	training/library/topics/hashicorp-vault/primer.md
security/a6c8d9ea	security	medium	vault,lease,renewal	What is a Vault lease and what happens when a lease expires?	Every dynamic secret and auth token has a lease with a TTL (time-to-live). Applications must renew the lease before expiry by calling the renew endpoint. If the lease expires without renewal, Vault automatically revokes the associated credential (e.g., drops the database user). Applications should handle renewal proactively to avoid sudden credential invalidation.	training/library/topics/hashicorp-vault/primer.md
security/b7d9eafb	security	easy	vault,agent,sidecar	What is Vault Agent and what problem does it solve?	Vault Agent is a client daemon that runs alongside applications (often as a sidecar in Kubernetes). It handles automatic auth token renewal, secret caching, and template rendering (writing secrets to files the app can read). This removes the need for applications to implement Vault client logic, token lifecycle management, and re-authentication after token expiry.	training/library/topics/hashicorp-vault/primer.md
security/c8eafb0c	security	medium	vault,audit,logging	How does Vault audit logging work and why is it critical?	Vault can log every API request and response to one or more audit devices (file, syslog, socket). Every secret read, write, auth event, and policy change is recorded with the accessor identity, timestamp, and request path. At least one audit device must be enabled -- Vault blocks all operations if it cannot write to any configured audit backend.	training/library/topics/hashicorp-vault/primer.md
security/d9fb0c1d	security	hard	vault,dr,replication	What is Vault disaster recovery replication and how does it differ from performance replication?	DR replication creates a standby cluster in another region that receives a full copy of all data but does not serve requests until promoted. Performance replication creates read replicas that can serve read requests locally but forward writes to the primary. DR replication is for failover; performance replication is for geographic distribution and read scaling.	training/library/topics/hashicorp-vault/primer.md
security/eafb1d2e	security	hard	vault,policies,hcl	How do Vault policies control access and what is a path-based policy?	Vault policies are written in HCL and define which paths (secret engines, auth methods, system endpoints) a token can access and with which capabilities (create, read, update, delete, list, sudo). For example: path "secret/data/myapp/*" { capabilities = ["read", "list"] } grants read-only access to all secrets under myapp. Policies are attached to tokens and auth method roles.	training/library/topics/hashicorp-vault/primer.md
security/fb0c2e3f	security	easy	vault,token,auth	What is a Vault token and what are root tokens used for?	Every authenticated request to Vault requires a token. Tokens have policies, TTLs, and can create child tokens. Root tokens have unlimited access and no TTL. They are generated during initialization (with the unseal keys) and should be revoked after initial setup. Use them only for emergency recovery or initial configuration -- never for application access.	training/library/topics/hashicorp-vault/primer.md
security/a1b2c3d4e5a7	security	easy	security, least-privilege	What is the principle of least privilege?	Every user, service, and process should have the minimum permissions required to do its job — nothing more. This applies to user accounts, service accounts, processes, network ports, and time-limited access.	training/library/topics/security-basics/primer.md
security/b2c3d4e5a7b8	security	easy	security, iam, groups	Why should IAM permissions be managed through groups rather than individual user policies?	Groups allow you to define a permission set once and apply it to many users. This is easier to audit, modify, and maintain than managing separate policies per user, and reduces the risk of permission drift or orphaned access.	training/library/topics/security-basics/primer.md
security/c3d4e5a7b8c9	security	easy	security, ssh, hardening	What two sshd_config settings are most critical for SSH hardening?	PasswordAuthentication no (keys only, prevents brute-force password attacks) and PermitRootLogin no (forces users to authenticate as themselves and then escalate, providing an audit trail).\n\nRemember: "XSS = Cross-Site Scripting." Attacker injects malicious scripts into web pages viewed by other users. Prevention: output encoding and CSP.	training/library/topics/security-basics/primer.md
security/d4e5a7b8c9d0	security	medium	security, iam, roles	Why are IAM roles preferred over long-lived access keys for service authentication?	Roles provide temporary credentials that expire automatically, reducing the blast radius if credentials are compromised. Access keys are long-lived, can be leaked, and must be manually rotated. Roles are assumed on-demand and never stored on disk.\n\nRemember: "CSRF = Cross-Site Request Forgery." Tricks a logged-in user's browser into making unwanted requests. Prevention: CSRF tokens and SameSite cookies.	training/library/topics/security-basics/primer.md
security/e5a7b8c9d0e1	security	medium	security, firewall, defense	What does "defense in depth" mean in practice for an operations engineer?	Multiple layers of security so that if one control fails, the next catches it: cloud security groups + host-level firewall + application authentication + encryption in transit. Never rely on a single layer. Each layer reduces the impact of a breach in another layer.	training/library/topics/security-basics/primer.md
security/a7b8c9d0e1f2	security	medium	security, iam, policy	In an AWS IAM policy, what do the Effect, Action, and Resource fields specify?	Effect is Allow or Deny. Action specifies which API operations are permitted (e.g., s3:GetObject, s3:ListBucket). Resource specifies which AWS resources the policy applies to (e.g., a specific S3 bucket ARN). Together they form a precise permission boundary.	training/library/topics/security-basics/primer.md
security/b8c9d0e1f2a3	security	medium	security, firewall, iptables	What is the security principle behind a default-deny firewall rule, and how is it implemented in iptables?	Default-deny means all traffic is blocked unless explicitly allowed by a preceding rule. In iptables: add specific ACCEPT rules first (e.g., SSH from internal network, HTTPS from anywhere, established connections), then end with "iptables -A INPUT -j DROP" to deny everything else.	training/library/topics/security-basics/primer.md
security/c9d0e1f2a3b4	security	hard	security, ssh, ciphers	What additional SSH hardening measures go beyond disabling password auth and root login?	Restrict access with AllowGroups, limit MaxAuthTries (e.g., 3), set idle timeouts (ClientAliveInterval 300, ClientAliveCountMax 2), disable X11Forwarding and AllowTcpForwarding unless needed, and enforce strong ciphers only (chacha20-poly1305, aes256-gcm) with secure key exchange algorithms (curve25519-sha256).	training/library/topics/security-basics/primer.md
security/d0e1f2a3b4c5	security	hard	security, cve, response	What is the CVE response workflow, and how should severity (CVSS score) drive response time?	1. Alert on new CVE. \n2. Assess severity: Critical 9.0-10.0 patch immediately, High 7.0-8.9 within days, Medium 4.0-6.9 within weeks, Low 0.1-3.9 normal cycle. \n3. Scope: identify affected systems. \n4. Mitigate with workaround if no patch. \n5. Patch affected packages/images. \n6. Verify the fix is applied everywhere.	training/library/topics/security-basics/primer.md
security/e1f2a3b4c5d6	security	hard	security, scanning, automation	How should vulnerability scanning be integrated into CI/CD, and what tools are commonly used?	Scan container images with trivy (trivy image --severity HIGH,CRITICAL myapp:v1.2.3), scan IaC with trivy config or checkov, and scan for secrets in git with trufflehog. Integrate these as CI pipeline gates that block deployment on critical/high findings. This shifts security left — catching issues before they reach production.	training/library/topics/security-basics/primer.md
security/a1e2f3b4c5d6	security	easy	opsec-mistakes, secrets, git	Why is deleting a file containing a secret in the next git commit insufficient?	Git stores full history. The secret remains accessible via git log -p or by checking out older commits. The secret must be rotated immediately, and history rewritten with git filter-repo if needed.	training/library/topics/opsec-mistakes/primer.md
security/b2f3a4c5d6e7	security	easy	opsec-mistakes, credentials, sharing	Why are shared credentials an operational security problem?	Shared credentials eliminate individual accountability (who made the change?), cannot be revoked for one person without rotating for everyone, and get weaker as they spread. Compliance frameworks require individual identities.\n\nRemember: "Rate limiting prevents brute force and DDoS." Implement at multiple layers: CDN, load balancer, application.	training/library/topics/opsec-mistakes/primer.md
security/c3a4b5d6e7f8	security	easy	opsec-mistakes, defaults	What is the risk of leaving default configurations in production?	Default passwords (e.g., admin/admin), services bound to 0.0.0.0, and unauthenticated data stores are the first things attackers check. Defaults are publicly documented and trivially exploitable.	training/library/topics/opsec-mistakes/primer.md
security/d4b5c6e7f8a9	security	medium	opsec-mistakes, iam, permissions	What is the Principle of Least Privilege, and what is a common violation?	Grant only the minimum permissions needed for the task, for the shortest duration. A common violation is IAM policies with Action: * and Resource: * or Kubernetes ClusterRoleBindings granting cluster-admin to developer groups.\n\nRemember: "JWT = JSON Web Token." Three parts: header.payload.signature (base64 encoded, dot-separated).\n\nGotcha: JWTs are signed, not encrypted — anyone can read the payload. Never store secrets in JWTs.	training/library/topics/opsec-mistakes/primer.md
security/e5c6d7f8a9b0	security	medium	opsec-mistakes, patching	Why are unpatched systems the number one entry point for attackers?	Known CVEs have public exploits within days of disclosure. Unpatched systems present known vulnerabilities with tested attack paths. A patching SLA (critical within 48h, high within 1 week) is essential.	training/library/topics/opsec-mistakes/primer.md
security/f6d7e8a9b0c1	security	medium	opsec-mistakes, containers	What is wrong with running containers as root, and how do you fix it?	Root inside a container maps to root on the host in many configurations, enabling container escape. Fix by adding a USER directive in the Dockerfile to run as a non-root user (e.g., USER appuser).	training/library/topics/opsec-mistakes/primer.md
security/a7e8f9b0c1d2	security	medium	opsec-mistakes, network	What is the security risk of a security group rule allowing inbound traffic from 0.0.0.0/0 on all ports?	It exposes every port on the instance to the entire internet, allowing any attacker to probe and exploit any running service. Rules should restrict to specific ports and source CIDR blocks.	training/library/topics/opsec-mistakes/primer.md
security/b8f9a0c1d2e3	security	hard	opsec-mistakes, secrets, remediation	What are the correct remediation steps when a secret is accidentally committed to git?	1) Rotate the secret immediately (assume compromised). \n2) Rewrite git history with git filter-repo (only after rotation). \n3) Force-push the cleaned branch. \n4) Invalidate cached copies in CI caches, container images, and artifacts.	training/library/topics/opsec-mistakes/primer.md
security/c9a0b1d2e3f4	security	hard	opsec-mistakes, monitoring, logging	What are the minimum security events you should monitor and alert on?	Authentication successes and failures, privilege escalation events, configuration changes on critical systems, network connection anomalies, and file integrity changes on sensitive paths (e.g., /etc/passwd, /etc/shadow).	training/library/topics/opsec-mistakes/primer.md
security/d0b1c2e3f4a5	security	hard	opsec-mistakes, containers, anti-patterns	What container security anti-patterns beyond running as root should you avoid?	Using the :latest tag (no reproducibility), running privileged containers, not scanning images for CVEs, mounting the Docker socket into containers (gives full host control), and storing secrets in environment variables visible via docker inspect.\n\nRemember: "CORS = Cross-Origin Resource Sharing." Browsers block cross-origin requests unless the server explicitly allows them via headers.	training/library/topics/opsec-mistakes/primer.md
security/e1c2d3f4a5b6	security	medium	opsec-mistakes, supply-chain, scanning	What is a software supply chain attack, and how do you defend against it?	An attacker compromises a dependency (library, container base image, CI plugin) to inject malicious code into your build. Defend with: dependency scanning (Dependabot, Snyk, Trivy), pinning versions with checksums, reviewing dependency updates, using signed images, and auditing CI pipeline plugins.	
security/f2d3e4a5b6c7	security	hard	opsec-mistakes, secrets, rotation	What is a secret rotation SLA, and what are reasonable targets?	A secret rotation SLA defines the maximum time a credential can live before mandatory rotation. Reasonable targets: API keys and tokens — 90 days, database passwords — 90 days, service account keys — 180 days, emergency/break-glass credentials — after every use. Automate rotation or enforce via expiry policies.	
security/a3e4f5b6c7d8	security	hard	opsec-mistakes, detection, exfiltration	How do you detect credential exfiltration from a compromised host?	Monitor for: unusual outbound DNS queries (data tunneling), unexpected API calls from the host's identity, access from new IP ranges or geolocations, credential use outside normal hours, and secrets accessed that the service does not normally use. Tools: CloudTrail anomaly detection, SIEM correlation rules, canary tokens (honeypot credentials that alert on use).	
security/b4f5a6c7d8e9	security	medium	opsec-mistakes, secrets, env-vars	Why are environment variables a poor choice for storing secrets in production?	Environment variables are visible via /proc/<pid>/environ, docker inspect, ps eww, and crash dumps. They leak into child processes, logging, and debug output. Use a secrets manager (Vault, AWS Secrets Manager, SOPS) that injects secrets at runtime via mounted files or direct API calls with short-lived tokens.	
security/c5a6b7d8e9f0	security	medium	opsec-mistakes, hardening, benchmark	What are CIS Benchmarks, and how do you use them to harden systems?	CIS Benchmarks are prescriptive security configuration guides for OSes, cloud providers, databases, and containers. Use automated scanners (CIS-CAT, Lunar, kube-bench for Kubernetes) to audit systems against the benchmark, then remediate failures. Run scans on every new AMI/image build and periodically in production.	
security/d6b7c8e9f0a1	security	easy	opsec-mistakes, secrets, prevention	What tools can prevent secrets from being committed to a git repository?	Pre-commit hooks using tools like git-secrets, detect-secrets, or truffleHog scan staged changes for high-entropy strings, known key patterns (AWS keys, private keys), and custom regex rules. Install as a pre-commit hook so every commit is checked before it reaches the repo.	

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Interview: CI Vuln Scan Failed](../../../../library/interview-scenarios/06-ci-vuln-scan-failed.md) (Scenario, L2) — Security Scanning
- Lab: Trivy Scan Remediation *(CLI)* (Lab, L1) — Security Scanning
- [Runbook: CVE Response (Critical Vulnerability)](../../../../library/runbooks/security/cve-response.md) (Runbook, L2) — Security Scanning
- [Security Basics (Ops-Focused)](../../../../library/topics/security-basics/index.md) (Topic Pack, L1) — Security Scanning
- [Security Drills](../../../../library/drills/security_drills.md) (Drill, L2) — Security Scanning
- [Security Scanning](../../../../library/topics/security-scanning/index.md) (Topic Pack, L1) — Security Scanning
- [Skillcheck: Security (Expanded)](../../../../library/skillchecks/security.skillcheck.md) (Assessment, L2) — Security Scanning

<!-- wiki:related:end -->
