[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fbt-threat-intelligence-application":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","bt-threat-intelligence-application","Bt Threat Intelligence Application","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,52,55,58,61,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":8,"name":9,"count":11},{"key":53,"name":54,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":56,"name":57,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":59,"name":60,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":62,"name":63,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":65,"name":66,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":163,"explanation":165},"019fad71-e859-744c-a004-a50148956d42",1,"In basic threat intelligence terminology, what is an IOC (Indicator of Compromise)?",[153,156,159,162],{"key":154,"text":155},"a","A written policy document that describes how an organization should respond to any incident.",{"key":157,"text":158},"b","A budget line item used to justify purchasing new detection and response tooling.",{"key":160,"text":161},"c","A formal certification that proves a system has never been compromised by an attacker.",{"key":163,"text":164},"d","An observable artifact -- a file hash, IP, or domain -- tied to malicious activity.","An IOC is a concrete, observable piece of evidence (a hash, an IP, a domain, a registry key, etc.) that has been seen in connection with malicious activity, and can be searched for or matched against telemetry.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":157,"explanation":178},"019fad71-e85b-73ca-8f1d-f2fd0b924d6f","How does a TTP (Tactics, Techniques, and Procedures) differ from a simple IOC like a file hash?",[170,172,174,176],{"key":154,"text":171},"A TTP is always encrypted, while an IOC is always sent in plain text over the network.",{"key":157,"text":173},"A TTP describes the attacker's behavior pattern, while an IOC is a static artifact of one instance of it.",{"key":160,"text":175},"There is no real difference; TTP is just another name analysts use for the same kind of hash-based indicator.",{"key":163,"text":177},"A TTP only applies to nation-state actors, while IOCs only apply to financially motivated criminal groups.","A TTP captures a behavioral pattern (e.g., using a scheduled task for persistence), which tends to be reused across many campaigns, whereas an IOC like a hash is a single, easily changed artifact tied to one specific sample or infrastructure instance.",{"id":180,"topic":9,"difficulty":181,"body":182,"options":183,"correct_key":163,"explanation":192},"019fad71-e85b-7cb0-82e6-921a1b70983d",2,"The Pyramid of Pain model ranks indicator types by how much difficulty they cause an attacker when defenders detect and act on them. According to this model, why are hash values considered 'easy' for an attacker to deal with, compared to TTPs?",[184,186,188,190],{"key":154,"text":185},"Attackers are physically incapable of generating more than one hash per malware family.",{"key":157,"text":187},"Hash values are legally protected information, so defenders cannot use them to block anything.",{"key":160,"text":189},"Hash values never appear in any threat intelligence feed, so defenders rarely act on them at all.",{"key":163,"text":191},"An attacker can trivially change a file's hash by recompiling it, at almost no cost.","In the Pyramid of Pain, hashes sit at the bottom because they are trivial and cheap for an attacker to change (a single byte change alters the hash), while TTPs sit at the top because changing fundamental behavior requires significant retooling and cost.",{"id":194,"topic":9,"difficulty":150,"body":195,"options":196,"correct_key":154,"explanation":205},"019fad71-e85d-7dce-b0af-0c8b13df29a1","What is the main purpose of MITRE ATT&CK's basic structure of 'tactics' and 'techniques'?",[197,199,201,203],{"key":154,"text":198},"Tactics represent the attacker's goal at a stage; techniques describe how to achieve it.",{"key":157,"text":200},"Tactics describe legal frameworks for prosecuting attackers, and techniques describe court procedures.",{"key":160,"text":202},"Tactics are only used for physical building security, and techniques are only used for network security.",{"key":163,"text":204},"Tactics list specific malware family names, and techniques list the antivirus vendors that detect them.","In MITRE ATT&CK, a tactic is the 'why' (the adversary's objective, such as persistence or lateral movement), and a technique is a specific 'how' that can achieve that objective, giving defenders a shared vocabulary to map observed behavior.",{"id":207,"topic":9,"difficulty":181,"body":208,"options":209,"correct_key":157,"explanation":218},"019fad71-e85e-78a2-aa09-a1187e932fc5","An analyst downloads a free, publicly available list of IP addresses labeled as 'malicious' from a community feed with no documented update or removal policy. What is the most important thing to check before using this feed for automatic blocking?",[210,212,214,216],{"key":154,"text":211},"Whether the file is formatted in CSV or JSON, since automatic blocking only works with one specific format.",{"key":157,"text":213},"How the feed handles aging and false positives, since IPs are reassigned often and stale entries can block traffic.",{"key":160,"text":215},"Whether the feed provider has a visually appealing website, since a professional site implies accurate data.",{"key":163,"text":217},"Whether the feed is written in the analyst's native language, since translation errors would otherwise make matching impossible.","IP addresses churn quickly (cloud providers reassign them, shared hosting rotates tenants), so a feed without a clear aging\u002Fremoval policy risks including stale entries that will cause false positives if used for automatic blocking without validation.",{"id":220,"topic":9,"difficulty":150,"body":221,"options":222,"correct_key":154,"explanation":231},"019fad71-e860-7cdc-9b93-9e923ad04e03","Which of the following best describes the difference between strategic, operational, and tactical threat intelligence?",[223,225,227,229],{"key":154,"text":224},"Strategic intel informs leadership risk decisions, operational intel supports campaign planning, and tactical intel gives detail analysts use directly.",{"key":157,"text":226},"Strategic intel is only about stock market trends, operational intel is only about server uptime, and tactical intel is only about physical security guards.",{"key":160,"text":228},"The three terms are interchangeable and any threat intelligence report can be labeled with any of the three names.",{"key":163,"text":230},"Strategic intel is always classified top secret, operational intel is always unclassified, and tactical intel does not exist in practice.","These are commonly used tiers of intelligence: strategic intel targets executives and long-term risk posture, operational intel supports understanding of ongoing or upcoming campaigns\u002Factor behavior, and tactical intel is the technical, immediately actionable detail (IOCs, TTPs) analysts use day to day.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":181,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]