[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fbt-digital-forensics-fundamentals":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,43,46,49,52,55,58,61,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":8,"name":9,"count":11},{"key":44,"name":45,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":47,"name":48,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":50,"name":51,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":53,"name":54,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":56,"name":57,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":59,"name":60,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":62,"name":63,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":65,"name":66,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,192,205,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fad71-e765-7157-bf79-42decada6e29",1,"What is digital forensics fundamentally concerned with?",[153,156,159,162],{"key":154,"text":155},"a","Identifying, preserving, analyzing, and presenting digital evidence in a way that its integrity can be verified and it can withstand scrutiny.",{"key":157,"text":158},"b","Removing all traces of an intrusion from a system as fast as possible so operations can resume.",{"key":160,"text":161},"c","Encrypting sensitive files so that only authorized investigators can ever open them.",{"key":163,"text":164},"d","A penetration-testing technique used to gain access to a system before an incident occurs, focused on exploiting weaknesses rather than examining evidence afterward.","Digital forensics is about identifying, preserving, analyzing, and presenting evidence while keeping its integrity intact — it is not about post-incident cleanup, encrypting files, or offensive testing.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":163,"explanation":178},"019fad71-e76c-72ae-b455-aa69c54f9b3c","What does 'chain of custody' refer to in an investigation?",[170,172,174,176],{"key":154,"text":171},"A legal requirement that evidence only ever be stored on removable media, regardless of how its custody is otherwise documented.",{"key":157,"text":173},"A checklist confirming that antivirus signatures on the evidence system are up to date.",{"key":160,"text":175},"The order in which an analyst escalates an alert to management during triage, documented separately from any evidence-related records.",{"key":163,"text":177},"A documented, unbroken record of who handled a piece of evidence, when, and what was done to it, from collection to presentation.","Chain of custody is the unbroken, documented record of everyone who handled a piece of evidence and what was done to it, which is what allows its integrity to be verified later.",{"id":180,"topic":9,"difficulty":150,"body":181,"options":182,"correct_key":157,"explanation":191},"019fad71-e773-72d8-8c92-6561365b6217","Why does a broken or incomplete chain of custody weaken a forensic case?",[183,185,187,189],{"key":154,"text":184},"Because it means the evidence was collected using an outdated tool.",{"key":157,"text":186},"Because unexplained gaps in who handled the evidence let opposing parties argue it may have been altered, making it less reliable or inadmissible.",{"key":160,"text":188},"Because it means the analyst needs to redo the entire investigation from scratch, discarding all findings gathered up to that point regardless of whether they were independently obtained.",{"key":163,"text":190},"Because it automatically proves the evidence is fake.","A gap in custody documentation does not prove tampering happened, but it removes the ability to rule it out, which is exactly what an opposing party can use to challenge the evidence's reliability.",{"id":193,"topic":9,"difficulty":150,"body":194,"options":195,"correct_key":163,"explanation":204},"019fad71-e778-73f9-95d3-c9e1a19b4f00","In the context of evidence collection, what does 'volatility' refer to?",[196,198,200,202],{"key":154,"text":197},"How dangerous a piece of malware is to the organization's network, independent of how quickly any related data might be lost.",{"key":157,"text":199},"How difficult a piece of evidence is to encrypt during transport, rather than how quickly it might disappear if left uncaptured.",{"key":160,"text":201},"How many analysts are required to sign off before evidence can be examined.",{"key":163,"text":203},"How quickly a piece of data will be lost or overwritten if nothing is done to capture it.","Volatility describes how quickly evidence disappears without intervention — RAM contents vanish on power loss, while disk data persists much longer, which is why volatile data is prioritized for early collection.",{"id":206,"topic":9,"difficulty":207,"body":208,"options":209,"correct_key":160,"explanation":218},"019fad71-e77c-703e-aacc-79ac950a6f2f",2,"Per the general order of volatility, which should typically be captured first when both are within scope: RAM or a full disk image?",[210,212,214,216],{"key":154,"text":211},"Neither matters, since both contain exactly the same information at any given moment.",{"key":157,"text":213},"The disk image, because RAM contents are automatically preserved by the operating system after a crash.",{"key":160,"text":215},"RAM, because its contents disappear as soon as the system loses power, unlike data already written to disk.",{"key":163,"text":217},"The disk image, because RAM cannot legally be used as evidence in most jurisdictions, and only persistent storage is considered valid for any subsequent legal proceeding.","RAM is far more volatile than disk data: its contents are lost the moment power is removed, so it is generally prioritized for capture ahead of a disk image when both are in scope.",{"id":220,"topic":9,"difficulty":207,"body":221,"options":222,"correct_key":154,"explanation":231},"019fad71-e77d-747a-85b8-b9a27f22fe97","An analyst arrives at a workstation that is still powered on and believed to be compromised. What is the most appropriate immediate action?",[223,225,227,229],{"key":154,"text":224},"Assess the situation and, if volatile data is within scope, capture memory and other volatile artifacts before considering how to power the system down.",{"key":157,"text":226},"Immediately pull the power cable to stop any further damage to the system.",{"key":160,"text":228},"Log in as the affected user and browse the file system to look for anything suspicious.",{"key":163,"text":230},"Perform a normal operating system shutdown so the system closes all applications cleanly, on the assumption that a graceful shutdown poses no risk to any potentially recoverable evidence.","Pulling the plug or shutting down immediately loses volatile evidence and can trigger anti-forensic cleanup; a normal shutdown can also run scripts that destroy evidence. Assessing the situation and capturing volatile data first follows the order of volatility.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":207,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]