[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fbt-crisis-communication-management":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","bt-crisis-communication-management","Bt Crisis Communication Management","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,37,40,43,46,49,52,55,58,61,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":8,"name":9,"count":11},{"key":38,"name":39,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":41,"name":42,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":44,"name":45,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":47,"name":48,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":50,"name":51,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":53,"name":54,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":56,"name":57,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":59,"name":60,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":62,"name":63,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":65,"name":66,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fad71-e5b9-76bb-b1ab-20468e624118",1,"During an active security incident, an organization designates a single spokesperson to speak externally, instead of letting any engineer answer questions from journalists or customers directly. What is the main benefit of this practice?",[153,156,159,162],{"key":154,"text":155},"a","It keeps external messaging consistent and accurate, avoiding contradictory statements from different people.",{"key":157,"text":158},"b","It guarantees the incident will be resolved faster, since a spokesperson can fix technical problems personally.",{"key":160,"text":161},"c","It removes any legal obligation to notify affected customers, since only one person is allowed to speak.",{"key":163,"text":164},"d","It means engineers no longer need to report incident details internally to anyone.","A single designated spokesperson prevents the confusion and reputational damage that comes from multiple people giving different, possibly conflicting, accounts of the same incident to the outside world. It does not speed up technical resolution or remove notification obligations.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":163,"explanation":178},"019fad71-e687-767c-99ea-ef5ee09043b3","Early in an incident, before the root cause or full scope is known, a team issues a short 'holding statement' acknowledging that something is being investigated. What is the purpose of a holding statement?",[170,172,174,176],{"key":154,"text":171},"To publicly name the exact vulnerability and attacker technique before the investigation is complete, treating maximum technical transparency as more urgent than protecting the ongoing investigation.",{"key":157,"text":173},"To promise a fixed resolution date that the team has not yet confirmed is achievable.",{"key":160,"text":175},"To replace the need for any further communication once it is published.",{"key":163,"text":177},"To acknowledge awareness of the issue and show the situation is being actively handled, without speculating on unconfirmed details.","A holding statement is a short, factual acknowledgment that buys time for investigation while showing stakeholders the situation is being taken seriously. It deliberately avoids unconfirmed technical detail or promises the team cannot yet back up.",{"id":180,"topic":9,"difficulty":181,"body":182,"options":183,"correct_key":157,"explanation":192},"019fad71-e690-7b70-84df-1d6fbca0ac4e",2,"Before any external statement about a data-related incident goes out, it is routed through legal counsel for review. Why is this step generally required?",[184,186,188,190],{"key":154,"text":185},"Legal counsel is responsible for actually writing all the technical remediation steps in the statement, effectively replacing the engineering team's role in describing the fix.",{"key":157,"text":187},"Legal counsel checks that wording does not create unintended liability and that it meets applicable notification obligations.",{"key":160,"text":189},"Legal review exists only to slow down communication and has no real bearing on the content.",{"key":163,"text":191},"Legal counsel decides which engineer will fix the underlying vulnerability.","Legal review exists because wording choices can create liability (admissions of fault, inaccurate claims) or fail to meet notification requirements. It is a substantive content check, not a technical remediation task or a delay for its own sake.",{"id":194,"topic":9,"difficulty":181,"body":195,"options":196,"correct_key":154,"explanation":205},"019fad71-e695-7ed0-ba20-7c9ae8b570db","During an active incident, an employee posts on their personal social media account: 'looks like we got hacked, pretty bad, more details soon.' What risk does this create for the organization's crisis communication effort?",[197,199,201,203],{"key":154,"text":198},"It creates an uncontrolled, unofficial disclosure that can spread inaccurate details and undercut the coordinated official message.",{"key":157,"text":200},"It guarantees the incident will be resolved sooner, since more people are now aware of it.",{"key":160,"text":202},"None, since personal accounts are never associated with the employer by anyone reading them.",{"key":163,"text":204},"It fulfills the organization's legal notification obligation to affected customers automatically, making any further official notice process unnecessary.","An unofficial, uncoordinated post can leak premature or inaccurate detail, get amplified before the organization has verified facts, and conflict with the eventual official statement — undermining message consistency, which is exactly what a crisis communication plan tries to protect.",{"id":207,"topic":9,"difficulty":150,"body":208,"options":209,"correct_key":157,"explanation":218},"019fad71-e697-7a90-87a1-e37b18519c45","A company notifies its board of directors about an ongoing incident with more technical detail (specific systems, exploit method) than it initially includes in a public customer notice, which focuses on impact and recommended actions. Why does this difference in content make sense?",[210,212,214,216],{"key":154,"text":211},"Because board members always need less information than customers about any topic.",{"key":157,"text":213},"Because each audience needs information tailored to what they must decide or do, and customers generally do not need internal technical detail to act.",{"key":160,"text":215},"Because customers are legally forbidden from ever receiving any technical information about an incident, under every jurisdiction and regulatory regime without exception.",{"key":163,"text":217},"Because the board notice should always be published publicly at the same time as the customer notice.","Effective incident communication is tailored per audience: the board needs enough detail to oversee risk and decisions, while customers primarily need to understand impact and what action (if any) to take. Neither audience needs the same level or type of detail as the other by default.",{"id":220,"topic":9,"difficulty":181,"body":221,"options":222,"correct_key":163,"explanation":231},"019fad71-e69e-754d-8148-48c22243f5eb","A team maintains a public status page during an incident. Why is it important that every update posted there be verified before publishing, rather than posted as soon as someone has a guess?",[223,225,227,229],{"key":154,"text":224},"Verifying updates before posting is required only for incidents involving payment data, never for any other kind of incident.",{"key":157,"text":226},"Status pages are only ever read by internal engineers, so accuracy has no external consequence.",{"key":160,"text":228},"Once posted, a status page update can never legally be corrected or updated again.",{"key":163,"text":230},"An inaccurate public update that later has to be retracted damages trust more than a slightly delayed, accurate one.","A public status page is often the primary source stakeholders check; an update that turns out wrong and must be walked back erodes credibility more than a brief delay while facts are confirmed. This applies broadly, not just to payment-related incidents.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":181,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]