[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fcse-container-workload-security":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","cse-container-workload-security","Cse Container Workload Security","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,55,58,61,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":8,"name":9,"count":11},{"key":56,"name":57,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":59,"name":60,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":62,"name":63,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":65,"name":66,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,192,205,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fab52-a999-7c9f-9cd0-19ae04eff71d",1,"What is the primary security purpose of cryptographically signing a container image before it is pushed to a registry?",[153,156,159,162],{"key":154,"text":155},"a","It lets consumers verify the image was produced by a trusted publisher and has not been tampered with since signing",{"key":157,"text":158},"b","It compresses the image layers so pulls complete faster across slow network links",{"key":160,"text":161},"c","It automatically removes any known-vulnerable packages from the final image layers",{"key":163,"text":164},"d","It replaces the need for a container registry by embedding the image inside the signature file","Image signing (e.g. with cosign\u002FSigstore or Notary) binds a cryptographic signature to the image digest. At deploy time, an admission controller can verify that signature against a trusted key\u002Fidentity, proving provenance and integrity, but it does not compress images, patch vulnerabilities, or replace the registry.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":163,"explanation":178},"019fab52-a99f-7144-9c5a-0a503d7194f8","What does an SBOM (Software Bill of Materials) provide for a container image?",[170,172,174,176],{"key":154,"text":171},"A record of which Kubernetes nodes the image's pods were scheduled on during the last 30 days",{"key":157,"text":173},"The CPU and memory limits that should be applied to any pod running that image",{"key":160,"text":175},"A list of the RBAC roles that were bound to the service account used by the workload",{"key":163,"text":177},"A structured inventory of the libraries, packages, and their versions included in the image","An SBOM enumerates every component (OS packages, language libraries, transitive dependencies) and their versions baked into an image. It is what security teams cross-reference against vulnerability databases to know exactly what is exposed when a new CVE is disclosed; it says nothing about scheduling, resource limits, or RBAC.",{"id":180,"topic":9,"difficulty":150,"body":181,"options":182,"correct_key":157,"explanation":191},"019fab52-a9a0-7821-92d6-69e88e669248","What is the security role of a Kubernetes admission controller such as OPA Gatekeeper or Kyverno?",[183,185,187,189],{"key":154,"text":184},"It scans running container filesystems every night and deletes any file that matches a malware signature",{"key":157,"text":186},"It intercepts API server requests after auth and can validate or mutate the object before it is persisted, enforcing policy.",{"key":160,"text":188},"It replaces kube-proxy to route traffic between pods based on network policy rules",{"key":163,"text":190},"It issues TLS certificates to nodes so kubelet can authenticate to the API server","Admission controllers (validating and mutating webhooks) sit in the API request pipeline after authentication and authorization but before the object is written to etcd. Policy engines like OPA Gatekeeper or Kyverno use this hook to enforce rules (e.g. deny privileged: true) or mutate manifests (e.g. inject defaults). They are not runtime file scanners, network routers, or certificate authorities.",{"id":193,"topic":9,"difficulty":150,"body":194,"options":195,"correct_key":154,"explanation":204},"019fab52-a9a1-7a89-9c6b-c832c8ef8eeb","Kubernetes Pod Security Standards define three policy levels. Which set correctly names them from most permissive to most restrictive?",[196,198,200,202],{"key":154,"text":197},"Privileged, Baseline, Restricted",{"key":157,"text":199},"Basic, Standard, Premium",{"key":160,"text":201},"Public, Internal, Confidential",{"key":163,"text":203},"Open, Locked, Sealed","The Pod Security Standards define exactly three levels: Privileged (unrestricted, for trusted system workloads), Baseline (blocks known privilege escalations while staying broadly compatible), and Restricted (enforces current pod hardening best practices such as dropping all capabilities and requiring non-root).",{"id":206,"topic":9,"difficulty":207,"body":208,"options":209,"correct_key":157,"explanation":218},"019fab52-a9a2-79c9-af15-71102b6deae9",2,"A runtime container security tool like Falco primarily works by doing what?",[210,212,214,216],{"key":154,"text":211},"Statically parsing the Dockerfile before the image is built to flag insecure base images",{"key":157,"text":213},"Observing kernel-level syscalls and container events at runtime and matching them against rules to flag anomalous behavior.",{"key":160,"text":215},"Diffing successive image tags in the registry to detect unexpected layer changes",{"key":163,"text":217},"Signing the running container's process list and pushing it as an attestation to a transparency log","Falco (and similar runtime security tools) taps into kernel syscalls (via eBPF or a kernel module) and Kubernetes audit events, evaluating them in real time against detection rules -- e.g. alerting when a shell is spawned in a container that never does so, or when a sensitive file is read. This is runtime behavioral detection, not static Dockerfile analysis, registry diffing, or attestation signing.",{"id":220,"topic":9,"difficulty":150,"body":221,"options":222,"correct_key":163,"explanation":231},"019fab52-a9a3-7cda-bea6-c5f869ef6b39","Why is storing a sensitive value in a plain Kubernetes Secret object, without any additional controls, not sufficient confidentiality protection on its own?",[223,225,227,229],{"key":154,"text":224},"Secrets can only be consumed by pods running on the same node where the Secret was created",{"key":157,"text":226},"Kubernetes Secrets are stored using a one-way hash, so the original value can never be retrieved even by the cluster administrator",{"key":160,"text":228},"Secrets are automatically synced to every namespace in the cluster, so restricting access is impossible",{"key":163,"text":230},"The Secret's value is only base64-encoded by default, which is trivially reversible by anyone who can read the Secret object.","By default, Kubernetes Secret data is base64-encoded, not encrypted -- encoding provides no confidentiality. Anyone with RBAC read access to the Secret object, or direct access to unencrypted etcd, can decode it instantly. This is why encryption at rest and RBAC restrictions (or an external secret store) are needed in addition to the Secret abstraction.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":207,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]