[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fbt-ir-playbook-execution":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","bt-ir-playbook-execution","Bt Ir Playbook Execution","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,49,52,55,58,61,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":8,"name":9,"count":11},{"key":50,"name":51,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":53,"name":54,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":56,"name":57,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":59,"name":60,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":62,"name":63,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":65,"name":66,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,192,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fad71-e823-7ca7-bfd8-473ec166f93d",1,"In the standard incident response lifecycle, what is the correct order of the three phases that come right after detection and analysis?",[153,156,159,162],{"key":154,"text":155},"a","Containment, then eradication, then recovery.",{"key":157,"text":158},"b","Recovery, then eradication, then containment.",{"key":160,"text":161},"c","Eradication, then recovery, then containment.",{"key":163,"text":164},"d","Recovery, then containment, then eradication.","After an incident is detected and analyzed, responders first contain it to stop further damage, then eradicate the root cause, and finally recover affected systems back to normal operation.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":163,"explanation":178},"019fad71-e825-72bc-9efc-4d0ac762422b","What is the primary purpose of containment during an active incident?",[170,172,174,176],{"key":154,"text":171},"To write the final incident report for management review, since documentation should always come before any technical action is taken to slow the incident down.",{"key":157,"text":173},"To permanently remove the vulnerability that allowed the attacker to get in.",{"key":160,"text":175},"To restore all affected systems to full production traffic immediately.",{"key":163,"text":177},"To stop the incident from spreading further or causing more damage while the team investigates.","Containment's goal is to limit the blast radius — stop the spread or ongoing damage — while the team still has time to investigate and plan eradication. Removing the root cause is eradication; restoring service is recovery; reporting comes later.",{"id":180,"topic":9,"difficulty":150,"body":181,"options":182,"correct_key":157,"explanation":191},"019fad71-e826-7792-bb97-852546ac91c8","What distinguishes short-term containment from long-term containment in an incident response playbook?",[183,185,187,189],{"key":154,"text":184},"Short-term containment always involves reimaging every affected system, while long-term containment never does.",{"key":157,"text":186},"Short-term containment applies a quick stopgap (like isolating a host) to stop the bleeding, while long-term containment sets up a more durable fix (like a rebuilt, patched system) while investigation continues.",{"key":160,"text":188},"There is no real difference; the two terms describe the exact same set of actions performed at any point in an incident.",{"key":163,"text":190},"Short-term containment is only used for insider-threat cases, while long-term containment is only used for external attacks.","Short-term containment is a fast, temporary action to stop immediate damage (e.g., network isolation), buying time. Long-term containment builds a more sustainable interim state — such as a patched, hardened, or rebuilt system on a clean segment — that can hold until full eradication and recovery are complete.",{"id":193,"topic":9,"difficulty":194,"body":195,"options":196,"correct_key":154,"explanation":205},"019fad71-e828-7f40-b578-0d7e05c93bbd",2,"A non-critical workstation is confirmed to be actively beaconing to an external address. Before eradicating anything, the responder wants to preserve evidence. What is the most appropriate immediate step?",[197,199,201,203],{"key":154,"text":198},"Isolate the workstation from the network (e.g., via a containment VLAN or blocking outbound traffic) while keeping it powered on to preserve volatile evidence for analysis.",{"key":157,"text":200},"Leave the workstation exactly as-is with full network access, and revisit it after the next scheduled maintenance window, since maintenance windows are always the appropriate time to address any security concern.",{"key":160,"text":202},"Power the workstation off completely to guarantee the malware cannot do anything further.",{"key":163,"text":204},"Reformat the workstation right away so it stops beaconing as quickly as possible.","Network isolation stops the beaconing and further damage without destroying volatile evidence (running processes, memory, open connections) the way a full power-off or immediate reformat would. Leaving it fully connected ignores the active threat.",{"id":207,"topic":9,"difficulty":150,"body":208,"options":209,"correct_key":157,"explanation":218},"019fad71-e82a-79d1-ad6a-03028da4c2f9","What does the eradication phase of an incident primarily involve?",[210,212,214,216],{"key":154,"text":211},"Reconnecting all affected systems to production traffic without further checks, since once the immediate incident is noticed, restoring full access is always the fastest path forward.",{"key":157,"text":213},"Removing the actual root cause of the compromise, such as malware, a rogue account, or the exploited vulnerability.",{"key":160,"text":215},"Notifying customers and regulators about the incident.",{"key":163,"text":217},"Running a tabletop exercise to test how the team would have responded.","Eradication removes what actually caused the incident so it cannot simply resurface — malicious files, backdoor accounts, and the exploited flaw itself. Reconnecting systems is recovery; notification is a communications task; tabletop exercises are a separate preparation activity.",{"id":220,"topic":9,"difficulty":194,"body":221,"options":222,"correct_key":160,"explanation":231},"019fad71-e82b-76ed-afe0-4c7a6de8b260","After eradicating malware from a server, the team is about to reintroduce it to production during recovery. What should they do first, before restoring full normal traffic?",[223,225,227,229],{"key":154,"text":224},"Route full production traffic back immediately, since eradication is already confirmed done.",{"key":157,"text":226},"Skip any further checks, since recovery simply means turning the system back on.",{"key":160,"text":228},"Bring the server back gradually with heightened monitoring, watching for any sign the same indicators of compromise reappear.",{"key":163,"text":230},"Restore the server from the most recent backup without checking when that backup was taken relative to the compromise, assuming that recency alone is always enough proof of safety.","Recovery is typically staged: systems come back under close monitoring so responders can catch any sign that eradication missed something, rather than assuming the job is finished the moment the malware file is deleted.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":194,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]