[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:database\u002Fsecurity-access":4,"config":215},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":115,"samples":129},"database","Database","","security-access","Security Access","en",75,2475,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,87,90,93,96,99,102,105,108,111,112],{"key":19,"name":20,"count":11},"backup-recovery","Backup Recovery",{"key":22,"name":23,"count":11},"data-modeling","Data Modeling",{"key":25,"name":26,"count":11},"indexing","Indexing",{"key":28,"name":29,"count":11},"mongodb-aggregation","Mongodb Aggregation",{"key":31,"name":32,"count":11},"mongodb-indexes-queries","Mongodb Indexes Queries",{"key":34,"name":35,"count":11},"mongodb-operations","Mongodb Operations",{"key":37,"name":38,"count":11},"mongodb-replication-sharding","Mongodb Replication Sharding",{"key":40,"name":41,"count":11},"mongodb-schema-modeling","Mongodb Schema Modeling",{"key":43,"name":44,"count":11},"mongodb-transactions-consistency","Mongodb Transactions Consistency",{"key":46,"name":47,"count":11},"mysql-indexes","Mysql Indexes",{"key":49,"name":50,"count":11},"mysql-innodb-transactions","Mysql Innodb Transactions",{"key":52,"name":53,"count":11},"mysql-operations","Mysql Operations",{"key":55,"name":56,"count":11},"mysql-query-optimization","Mysql Query Optimization",{"key":58,"name":59,"count":11},"mysql-replication-scaling","Mysql Replication Scaling",{"key":61,"name":62,"count":11},"mysql-types-constraints","Mysql Types Constraints",{"key":64,"name":65,"count":11},"nosql-models","Nosql Models",{"key":67,"name":68,"count":11},"performance-tuning","Performance Tuning",{"key":70,"name":71,"count":11},"pg-indexes","Pg Indexes",{"key":73,"name":74,"count":11},"pg-mvcc-vacuum","Pg Mvcc Vacuum",{"key":76,"name":77,"count":11},"pg-operations","Pg Operations",{"key":79,"name":80,"count":11},"pg-query-planning","Pg Query Planning",{"key":82,"name":83,"count":11},"pg-transactions-locking","Pg Transactions Locking",{"key":85,"name":86,"count":11},"pg-types-constraints","Pg Types Constraints",{"key":88,"name":89,"count":11},"query-optimization","Query Optimization",{"key":91,"name":92,"count":11},"redis-cluster-sharding","Redis Cluster Sharding",{"key":94,"name":95,"count":11},"redis-data-structures","Redis Data Structures",{"key":97,"name":98,"count":11},"redis-expiration-eviction","Redis Expiration Eviction",{"key":100,"name":101,"count":11},"redis-persistence","Redis Persistence",{"key":103,"name":104,"count":11},"redis-replication-sentinel","Redis Replication Sentinel",{"key":106,"name":107,"count":11},"redis-transactions-scripting","Redis Transactions Scripting",{"key":109,"name":110,"count":11},"replication-scaling","Replication Scaling",{"key":8,"name":9,"count":11},{"key":113,"name":114,"count":11},"transactions-isolation","Transactions Isolation",[116,120,123,126],{"key":117,"name":118,"count":119},"mongodb","MongoDB",450,{"key":121,"name":122,"count":119},"mysql","MySQL",{"key":124,"name":125,"count":119},"postgresql","PostgreSQL",{"key":127,"name":128,"count":119},"redis","Redis",[130,148,162,176,189,202],{"id":131,"topic":9,"difficulty":132,"body":133,"options":134,"correct_key":142,"explanation":147},"019f56bb-b6d9-7e6c-9ff7-18c1f1daee2c",1,"What is SQL injection?",[135,138,141,144],{"key":136,"text":137},"a","The database rejecting a query because its SQL syntax is invalid",{"key":139,"text":140},"b","An attacker overwhelming the database server with too many simultaneous open connections",{"key":142,"text":143},"c","An attacker changing a query's meaning by smuggling SQL through unvalidated input",{"key":145,"text":146},"d","A query running slowly because a filtered column has no supporting index","SQL injection happens when untrusted input is concatenated into a SQL string, so the input can change the statement's structure (add conditions, run extra statements) instead of being treated as a value. Option (b) describes a denial-of-service \u002F connection flood and (d) a performance issue — neither alters query logic.",{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":139,"explanation":161},"019f56bb-b6dc-7256-8393-860bde1da09a",2,"An application runs a query with a placeholder and binds the value separately:\n```sql\n-- SQL text (sent and parsed once):\nSELECT * FROM users WHERE email = ?;\n-- value supplied separately, as data:\nbind(1, 'alice@example.com')\n```\nWhy does binding the value as a parameter instead of concatenating it into the SQL text prevent SQL injection?",[153,155,157,159],{"key":136,"text":154},"The database automatically encrypts each bound parameter before storing or comparing it",{"key":139,"text":156},"The statement is parsed with the placeholder, so the value can only be used as data, not as SQL",{"key":142,"text":158},"Bound parameter values are capped at a fixed length, which blocks long injection payloads",{"key":145,"text":160},"The database carefully scans each parameter and automatically rejects any value that contains SQL keywords","With a parameterized (prepared) statement the SQL text — including the placeholder — is parsed and planned first; the supplied value is then bound purely as data and is never re-parsed as SQL, so it cannot add conditions or statements. Encryption (a) and keyword-blocking (d) are not how it works — a legitimate value may contain the word 'OR' or a quote and must still be accepted as data. Length capping (c) is unrelated.",{"id":163,"topic":9,"difficulty":164,"body":165,"options":166,"correct_key":145,"explanation":175},"019f56bb-b6e0-7bc8-ac04-04ebaac53e63",3,"A login check builds its query by concatenating the form input:\n```sql\nSELECT * FROM users WHERE username = '\u003Cinput>' AND password = '\u003Cinput>';\n```\nAn attacker submits `' OR '1'='1' -- ` as the username. What is the likely result?",[167,169,171,173],{"key":136,"text":168},"The query fails with a syntax error, so the login attempt is safely rejected",{"key":139,"text":170},"Only a user literally named `' OR '1'='1'` matches, so the query returns no rows",{"key":142,"text":172},"The database refuses the request automatically because the input contains a single quote",{"key":145,"text":174},"The WHERE turns always-true and `--` comments out the password check, bypassing login","The injected `'` closes the username string, `OR '1'='1'` makes the condition always true, and `--` comments out the rest (the password check). The query returns rows — often the first\u002Fadmin user — and authentication is bypassed. Databases do not reject quotes by themselves (c); once injected the input is valid SQL, so there is no syntax error (a).",{"id":177,"topic":9,"difficulty":132,"body":178,"options":179,"correct_key":136,"explanation":188},"019f56bb-b6e5-7965-9aa7-b624c433d902","According to the principle of least privilege, what privileges should a production application's database account have?",[180,182,184,186],{"key":136,"text":181},"Only the specific privileges its normal operations require, and nothing beyond that",{"key":139,"text":183},"Full superuser rights, so that a missing permission can never break a request",{"key":142,"text":185},"Every privilege on every table, restricted only to normal business hours",{"key":145,"text":187},"Exactly the same privileges as the developers who built the application","Least privilege means granting only the permissions a component needs to do its job, limiting the damage if it is compromised or has a bug. A superuser app account (b) turns any SQL injection or logic flaw into full database control. Time-based (c) or developer-matching (d) grants are not what least privilege means.",{"id":190,"topic":9,"difficulty":132,"body":191,"options":192,"correct_key":139,"explanation":201},"019f56bb-b6e6-7b33-b8a9-4c5addf3e5d6","What does `GRANT SELECT ON orders TO reporting;` do?",[193,195,197,199],{"key":136,"text":194},"It transfers ownership of the orders table to the reporting role",{"key":139,"text":196},"It allows the reporting role to read rows from orders, but not to change them",{"key":142,"text":198},"It grants the reporting role both full read and full write access to the entire orders table",{"key":145,"text":200},"It copies the orders table's rows into a new table owned by reporting","SELECT is the read privilege; GRANT SELECT lets the grantee query the table but gives no INSERT\u002FUPDATE\u002FDELETE (so not (c)). It does not change ownership (a) or copy data (d) — ownership and DDL are separate from data-access privileges.",{"id":203,"topic":9,"difficulty":150,"body":204,"options":205,"correct_key":142,"explanation":214},"019f56bb-b6e8-703c-8c93-38110ecfa529","An account currently has SELECT and INSERT on `payments`. After running:\n```sql\nREVOKE INSERT ON payments FROM app_user;\n```\nwhat can `app_user` still do on `payments`?",[206,208,210,212],{"key":136,"text":207},"Nothing, because REVOKE strips every privilege the account had on the table",{"key":139,"text":209},"Both SELECT and INSERT, since a REVOKE only applies after the server restarts",{"key":142,"text":211},"Only SELECT — INSERT is removed while the previously granted SELECT stays",{"key":145,"text":213},"Only INSERT, because REVOKE always keeps the most recently granted privilege","REVOKE removes exactly the named privilege (INSERT); the untouched SELECT grant remains, so the account can still read but no longer insert. REVOKE takes effect immediately (no restart, so (b) is wrong) and only affects the privileges you list (so (a) and (d) are wrong).",{"fields":216,"seniorities":391,"interview_shapes":392,"locales":397,"oauth":399,"question_count":402,"coach_enabled":403,"jd_match_enabled":403},[217,242,262,278,302,315,324,343,365,372,378,385],{"key":218,"name_tr":219,"name_en":219,"sort":132,"specializations":220},"backend","Backend",[221,224,227,230,233,236,239],{"key":222,"name":223,"field":218},"general","Genel",{"key":225,"name":226,"field":218},"go","Go",{"key":228,"name":229,"field":218},"python","Python",{"key":231,"name":232,"field":218},"java","Java",{"key":234,"name":235,"field":218},"csharp","C#\u002F.NET",{"key":237,"name":238,"field":218},"nodejs","Node.js",{"key":240,"name":241,"field":218},"php","PHP",{"key":243,"name_tr":244,"name_en":244,"sort":150,"specializations":245},"frontend","Frontend",[246,247,250,253,256,259],{"key":222,"name":223,"field":243},{"key":248,"name":249,"field":243},"javascript","JavaScript",{"key":251,"name":252,"field":243},"typescript","TypeScript",{"key":254,"name":255,"field":243},"react","React",{"key":257,"name":258,"field":243},"vue","Vue",{"key":260,"name":261,"field":243},"angular","Angular",{"key":263,"name_tr":264,"name_en":264,"sort":164,"specializations":265},"fullstack","Fullstack",[266,267,268,269,270,271,272,273,274,275,276,277],{"key":222,"name":223,"field":263},{"key":225,"name":226,"field":218},{"key":228,"name":229,"field":218},{"key":231,"name":232,"field":218},{"key":234,"name":235,"field":218},{"key":237,"name":238,"field":218},{"key":240,"name":241,"field":218},{"key":248,"name":249,"field":243},{"key":251,"name":252,"field":243},{"key":254,"name":255,"field":243},{"key":257,"name":258,"field":243},{"key":260,"name":261,"field":243},{"key":279,"name_tr":280,"name_en":280,"sort":281,"specializations":282},"devops-cloud","DevOps \u002F Cloud",4,[283,284,287,290,293,296,299],{"key":222,"name":223,"field":279},{"key":285,"name":286,"field":279},"aws","AWS",{"key":288,"name":289,"field":279},"gcp","GCP",{"key":291,"name":292,"field":279},"azure","Azure",{"key":294,"name":295,"field":279},"kubernetes","Kubernetes",{"key":297,"name":298,"field":279},"terraform","Terraform",{"key":300,"name":301,"field":279},"linux","Linux",{"key":303,"name_tr":304,"name_en":304,"sort":305,"specializations":306},"ai-engineer","AI Engineer",5,[307,308,309,312],{"key":222,"name":223,"field":303},{"key":228,"name":229,"field":303},{"key":310,"name":311,"field":303},"llm-rag","LLM\u002FRAG",{"key":313,"name":314,"field":303},"mlops","MLOps",{"key":5,"name_tr":316,"name_en":6,"sort":317,"specializations":318},"Veritabanı",6,[319,320,321,322,323],{"key":222,"name":223,"field":5},{"key":124,"name":125,"field":5},{"key":121,"name":122,"field":5},{"key":117,"name":118,"field":5},{"key":127,"name":128,"field":5},{"key":325,"name_tr":326,"name_en":327,"sort":328,"specializations":329},"mobile","Mobil","Mobile",7,[330,331,334,337,340],{"key":222,"name":223,"field":325},{"key":332,"name":333,"field":325},"ios-swift","iOS (Swift)",{"key":335,"name":336,"field":325},"android-kotlin","Android (Kotlin)",{"key":338,"name":339,"field":325},"flutter","Flutter",{"key":341,"name":342,"field":325},"react-native","React Native",{"key":344,"name_tr":345,"name_en":346,"sort":347,"specializations":348},"security","Güvenlik","Security",8,[349,350,353,356,359,362],{"key":222,"name":223,"field":344},{"key":351,"name":352,"field":344},"appsec","AppSec",{"key":354,"name":355,"field":344},"offensive-pentest","Offensive \u002F Pentest",{"key":357,"name":358,"field":344},"cloud-security","Cloud Security",{"key":360,"name":361,"field":344},"devsecops","DevSecOps",{"key":363,"name":364,"field":344},"blue-team-incident","Blue Team \u002F Incident",{"key":366,"name_tr":367,"name_en":368,"sort":369,"specializations":370},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[371],{"key":222,"name":223,"field":366},{"key":373,"name_tr":374,"name_en":374,"sort":375,"specializations":376},"data-engineer","Data Engineer",10,[377],{"key":222,"name":223,"field":373},{"key":379,"name_tr":380,"name_en":381,"sort":382,"specializations":383},"game-dev","Oyun Geliştirme","Game Development",11,[384],{"key":222,"name":223,"field":379},{"key":386,"name_tr":387,"name_en":387,"sort":388,"specializations":389},"ml-engineer","ML Engineer",12,[390],{"key":222,"name":223,"field":386},[14,15,16],{"junior":393,"mid":395,"senior":396},{"questions":394,"median_sec":3},20,{"questions":394,"median_sec":3},{"questions":394,"median_sec":3},[398,10],"tr",[400,401],"google","github",21750,true]