[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fcse-data-protection-governance":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","cse-data-protection-governance","Cse Data Protection Governance","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,61,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":8,"name":9,"count":11},{"key":62,"name":63,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":65,"name":66,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,180,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fab52-a9d5-7a67-9ee5-516ed6bee9de",1,"In cloud key management, what does BYOK (Bring Your Own Key) mean?",[153,156,159,162],{"key":154,"text":155},"a","The customer generates the encryption key outside the provider and imports it into the provider's KMS for use.",{"key":157,"text":158},"b","The cloud provider generates the key and never reveals its value to the customer under any circumstance. This design is also required under FIPS 140-3 to guarantee that provider-side hardware never exposes any customer key material in any deployment.",{"key":160,"text":161},"c","The customer stores encrypted data locally instead of uploading it to any cloud storage service at all.",{"key":163,"text":164},"d","The provider rotates all customer keys automatically every 24 hours regardless of the customer's policy.","BYOK means the customer creates and controls the key material outside the cloud provider, then imports it into the provider's key management service so the provider can use it for encryption operations while the customer retains origin control over the key.",{"id":167,"topic":9,"difficulty":168,"body":169,"options":170,"correct_key":163,"explanation":179},"019fab52-a9d6-7990-9f3a-b96b2f8c0c74",2,"How does HYOK (Hold Your Own Key) differ from BYOK from a security-governance perspective?",[171,173,175,177],{"key":154,"text":172},"HYOK is identical to BYOK; the two terms are used interchangeably by every cloud provider and vendor. Some vendors even document this equivalence explicitly in their compliance whitepapers as a certified interchangeable configuration option.",{"key":157,"text":174},"HYOK means the key is generated by the provider but exported to the customer once per year for review.",{"key":160,"text":176},"HYOK requires the customer to disable encryption entirely and rely only on network-layer access controls.",{"key":163,"text":178},"In HYOK the key material never leaves customer-controlled infrastructure; the provider calls out to it for each operation.","With HYOK, the key never resides inside the cloud provider's key store at all — it stays in customer-controlled infrastructure (e.g., an on-prem HSM), and the provider must make an external call to that infrastructure for every cryptographic operation, giving the customer the strongest operational control over key custody.",{"id":181,"topic":9,"difficulty":168,"body":182,"options":183,"correct_key":157,"explanation":192},"019fab52-a9d7-7685-b9a9-777705577afe","What is the primary purpose of envelope encryption in cloud KMS architectures?",[184,186,188,190],{"key":154,"text":185},"It encrypts data twice with the same key to add redundancy in case the first encryption pass is corrupted.",{"key":157,"text":187},"A data encryption key encrypts the bulk data, and that key itself is encrypted by a master key stored in the KMS.",{"key":160,"text":189},"It replaces symmetric encryption with a plaintext checksum so data integrity can be verified without any key.",{"key":163,"text":191},"It stores the master key alongside the encrypted data object so decryption never requires a network call. This pattern is specifically recommended by cloud vendors for latency-sensitive workloads because it removes the KMS round-trip from every single decrypt operation entirely.","Envelope encryption uses a data encryption key (DEK) to encrypt the actual payload, and a separate master\u002Fkey-encryption key (KEK) held in the KMS encrypts the DEK. This avoids sending large volumes of data through the KMS directly and lets the master key be rotated or access-controlled independently of bulk data.",{"id":194,"topic":9,"difficulty":150,"body":195,"options":196,"correct_key":163,"explanation":205},"019fab52-a9d8-707c-855f-5b93626e0e51","What is the security-relevant distinction between data residency and data sovereignty?",[197,199,201,203],{"key":154,"text":198},"They are the same concept; both refer only to which currency a cloud invoice is billed in for a customer.",{"key":157,"text":200},"Residency is about encryption algorithm choice, while sovereignty is about which team owns the backup schedule.",{"key":160,"text":202},"Residency governs who can access a database, while sovereignty governs which employees can view a dashboard. This separation mirrors how many regulators define 'operational control' scope for data-processing agreements, according to common industry usage.",{"key":163,"text":204},"Residency is about where data is physically stored, while sovereignty is about which jurisdiction's laws govern it.","Data residency refers to the physical or geographic location where data is stored, while data sovereignty refers to the legal jurisdiction whose laws apply to that data — data can be resident in one country yet still subject to another jurisdiction's legal reach depending on ownership, contracts, or the operating entity.",{"id":207,"topic":9,"difficulty":168,"body":208,"options":209,"correct_key":160,"explanation":218},"019fab52-a9d8-7918-917a-fd0c0cade640","A company must keep customer records within a specific country's borders due to a data-localization requirement. Which cloud architecture control most directly enforces this?",[210,212,214,216],{"key":154,"text":211},"Enabling multi-factor authentication for every administrator account that manages the storage service. This approach is typically paired with mandatory hardware token login for every administrator session across the organization without exception.",{"key":157,"text":213},"Applying a generic least-privilege IAM policy to the storage bucket without any location constraint.",{"key":160,"text":215},"Region-pinning storage and compute resources, combined with policies that block cross-region replication.",{"key":163,"text":217},"Increasing the retention period of audit logs so investigators can review access history for longer.","Region-pinning (restricting where resources are provisioned) combined with explicit controls that prevent cross-region replication or backup is the direct architectural mechanism for data localization. MFA, generic IAM policies, and log retention are good hygiene but do not by themselves constrain where the data physically lives.",{"id":220,"topic":9,"difficulty":150,"body":221,"options":222,"correct_key":154,"explanation":231},"019fab52-a9d9-73c2-9169-1c13ac1b09d3","What is the core function of a Data Loss Prevention (DLP) system in a cloud environment?",[223,225,227,229],{"key":154,"text":224},"It inspects content in motion, at rest, or in use to detect and act on sensitive data patterns before exposure occurs.",{"key":157,"text":226},"It replaces the need for identity and access management by granting access based solely on file size.",{"key":160,"text":228},"It encrypts every outbound network packet regardless of whether the payload contains sensitive content or not. This blanket encryption approach is often marketed as a full replacement for content inspection tooling in modern SASE architectures.",{"key":163,"text":230},"It automatically deletes any file older than a configured retention window without any content inspection.","A DLP system's core function is content inspection — scanning data in transit, at rest, or in use for sensitive patterns (like PII or credit card numbers) and enforcing policy actions (block, alert, quarantine) before that data is exposed or exfiltrated. It is not an access-control replacement, blanket encryption tool, or retention-based deletion mechanism.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":168,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]