[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fas-authentication-session":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","as-authentication-session","As Authentication Session","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,25,28,31,34,37,40,43,46,49,52,55,58,61,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":8,"name":9,"count":11},{"key":26,"name":27,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":29,"name":30,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":32,"name":33,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":35,"name":36,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":38,"name":39,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":41,"name":42,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":44,"name":45,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":47,"name":48,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":50,"name":51,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":53,"name":54,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":56,"name":57,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":59,"name":60,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":62,"name":63,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":65,"name":66,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":160,"explanation":165},"019faa33-1071-7f11-9efb-42155d1f28d4",1,"Why is storing passwords as a plain SHA-256 hash considered insecure, even though SHA-256 is a strong cryptographic hash function?",[153,156,159,162],{"key":154,"text":155},"a","SHA-256 produces a hash that is too short to be collision-resistant, making it feasible for an attacker to find two different passwords that hash to the identical digest",{"key":157,"text":158},"b","SHA-256 cannot be implemented in most programming languages without a paid license",{"key":160,"text":161},"c","SHA-256 is designed to be extremely fast, so attackers can try billions of guesses per second against a stolen hash dump",{"key":163,"text":164},"d","SHA-256 always produces the same output length regardless of input, which leaks the password length","General-purpose hash functions like SHA-256 are built for speed, which is exactly the wrong property for password storage: an attacker with a leaked hash database can run massively parallel brute-force or dictionary attacks on cheap hardware. Password hashing functions (bcrypt, scrypt, argon2) are deliberately slow and tunable to make each guess expensive.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":163,"explanation":178},"019faa33-1072-7c14-bcbe-24e4f0b82ce0","In the context of password hashing algorithms like bcrypt, what is the purpose of a per-user random salt?",[170,172,174,176],{"key":154,"text":171},"It speeds up the hashing computation by giving the algorithm a shorter input to process, cutting the time needed to verify a login on high-traffic authentication endpoints",{"key":157,"text":173},"It compresses the password to a fixed length before hashing so the database column can be smaller",{"key":160,"text":175},"It encrypts the hash so it can later be decrypted back to the original password for support requests",{"key":163,"text":177},"It ensures that two users with the same password get different stored hashes, defeating precomputed rainbow-table attacks","A salt is random data mixed into the input before hashing and stored alongside the hash. Because it differs per user, identical passwords produce different hashes, which makes precomputed lookup tables (rainbow tables) useless and forces an attacker to attack each hash individually.",{"id":180,"topic":9,"difficulty":181,"body":182,"options":183,"correct_key":154,"explanation":192},"019faa33-1073-75f3-a1bc-268293f42f0b",2,"What does the 'work factor' (or cost parameter) in bcrypt control?",[184,186,188,190],{"key":154,"text":185},"How many rounds of internal computation are performed, directly controlling how slow (and therefore expensive to brute-force) each hash operation is",{"key":157,"text":187},"How many previous passwords are remembered to prevent password reuse, a history list the authentication service consults on every password-change request before accepting the new value",{"key":160,"text":189},"The maximum allowed length of the input password before it is truncated",{"key":163,"text":191},"The number of database replicas that must acknowledge the write before the hash is considered stored","bcrypt's work factor is an exponential cost parameter: increasing it doubles the computation time per hash. This lets operators tune hashing cost upward as hardware gets faster, keeping brute-force attacks expensive over time.",{"id":194,"topic":9,"difficulty":150,"body":195,"options":196,"correct_key":154,"explanation":205},"019faa33-1073-7e1a-8115-c97ac264ec42","A JWT (JSON Web Token) is typically composed of which three parts, separated by dots?",[197,199,201,203],{"key":154,"text":198},"Header, payload, and signature",{"key":157,"text":200},"Public key, private key, and ciphertext",{"key":160,"text":202},"Session ID, CSRF token, and expiry timestamp",{"key":163,"text":204},"Issuer, subject, and encrypted payload","A JWT is `header.payload.signature`, each part base64url-encoded. The header describes the algorithm and token type, the payload holds claims (like user ID and expiry), and the signature lets the receiver verify the token was not tampered with.",{"id":207,"topic":9,"difficulty":181,"body":208,"options":209,"correct_key":163,"explanation":218},"019faa33-1074-766a-949c-1539cba223fe","What is the security risk of the JWT `alg: none` attack?",[210,212,214,216],{"key":154,"text":211},"It doubles the size of the payload, making the token too large for most HTTP headers, which would cause the server to reject the request outright with a header-size-limit error before any signature check occurs",{"key":157,"text":213},"It forces the server to fall back to plaintext HTTP instead of HTTPS for that request",{"key":160,"text":215},"It causes the token to expire immediately, resulting in denial of service for legitimate users",{"key":163,"text":217},"A poorly implemented verifier that trusts the token's own `alg` header may accept an unsigned token as valid, letting an attacker forge arbitrary claims","The JWT header's `alg` field is attacker-controlled input. If a library naively honors whatever `alg` the token claims, an attacker can set `alg: none`, strip the signature, and the server may accept the forged token as authentic. The fix is to whitelist expected algorithms on the verifying side and never derive trust from the token itself.",{"id":220,"topic":9,"difficulty":150,"body":221,"options":222,"correct_key":160,"explanation":231},"019faa33-1074-7eee-9de7-804770426fee","What does the `exp` (expiration) claim in a JWT payload control?",[223,225,227,229],{"key":154,"text":224},"The maximum number of API endpoints the token is allowed to call",{"key":157,"text":226},"The encryption algorithm used to protect the token in transit, which the client and server negotiate separately from the token's own contents",{"key":160,"text":228},"The timestamp after which the token must be treated as expired and rejected by any verifier",{"key":163,"text":230},"The number of times the token can be refreshed before a new login is required","`exp` is a standard registered claim holding a Unix timestamp. Verifiers must check the current time against it and reject the token once that time has passed, which bounds how long a stolen token remains useful to an attacker.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":181,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]