[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fcse-detection-incident-response":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","cse-detection-incident-response","Cse Detection Incident Response","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":8,"name":9,"count":11},{"key":65,"name":66,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,192,205,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fab52-a9e8-75a3-9574-0e01a4de5aa5",1,"In AWS, what is the primary purpose of CloudTrail from a security detection standpoint?",[153,156,159,162],{"key":154,"text":155},"a","It records who made which API call, when, and from where.",{"key":157,"text":158},"b","It scans running workloads for malware signatures and quarantines infected files automatically.",{"key":160,"text":161},"c","It encrypts all data at rest across every AWS service so that stolen disks cannot be read by an attacker.",{"key":163,"text":164},"d","It replaces the need for IAM policies by enforcing access decisions directly at the network layer.","CloudTrail is an audit-logging service: it captures API calls (who, what action, when, source IP\u002Fidentity) across the account. It does not scan for malware, does not encrypt data, and is not an access-control mechanism — it is the evidence trail used for detection and investigation.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":154,"explanation":178},"019fab52-a9e9-7125-8778-4926c08b9828","CloudTrail distinguishes between 'management events' and 'data events'. Which statement correctly describes this distinction?",[170,172,174,176],{"key":154,"text":171},"Management events cover control-plane operations like creating or deleting resources (e.g., creating a bucket, modifying a security group), and are logged by default.",{"key":157,"text":173},"Data events are always enabled by default at no extra cost, while management events must be purchased separately.",{"key":160,"text":175},"Management events cover only billing changes, while data events cover only IAM changes, and the two never overlap.",{"key":163,"text":177},"Management events and data events are two names for the exact same log stream, kept only for backward compatibility.","Management events are control-plane actions (e.g., creating a bucket, modifying a security group) and are logged by default. Data events (e.g., S3 GetObject\u002FPutObject, Lambda invocations) are high-volume, opt-in, and typically cost extra — important for detecting things like mass object exfiltration.",{"id":180,"topic":9,"difficulty":150,"body":181,"options":182,"correct_key":160,"explanation":191},"019fab52-a9e9-7921-b3d8-6e1c527b75d5","Conceptually, what makes services like GuardDuty, Microsoft Defender for Cloud, or Google Security Command Center (SCC) different from a plain log viewer?",[183,185,187,189],{"key":154,"text":184},"They replace the need to collect any logs at all, since they generate their own independent evidence from network taps.",{"key":157,"text":186},"They physically isolate compromised hardware in the cloud provider's data center the moment an anomaly is detected.",{"key":160,"text":188},"They continuously analyze signals such as logs and network metadata against threat intelligence and behavioral models to surface findings.",{"key":163,"text":190},"They only work if the customer manually uploads known malware hashes into the service every day.","Cloud-native detection services correlate multiple signal sources (account activity, network flow metadata, DNS, threat-intel feeds) and apply anomaly\u002Fbehavioral detection to produce prioritized findings — they are analysis engines, not just log storage or viewers, and they do not perform physical hardware actions.",{"id":193,"topic":9,"difficulty":150,"body":194,"options":195,"correct_key":163,"explanation":204},"019fab52-a9ea-76eb-bdc8-a077f3484469","Why is 'log file integrity validation' (ensuring audit logs cannot be silently altered after being written) considered important for incident response?",[196,198,200,202],{"key":154,"text":197},"It makes the logs load faster in the console, which is purely a performance feature with no security value.",{"key":157,"text":199},"It allows the security team to edit past log entries to correct typos without anyone noticing.",{"key":160,"text":201},"It is required only for cosmetic compliance checkboxes and has no bearing on how an investigation is actually conducted.",{"key":163,"text":203},"It lets investigators prove that the audit trail they are analyzing has not been tampered with.","If an attacker who gains privileged access could quietly rewrite or delete audit logs, the trail used to reconstruct an incident would be unreliable. Integrity validation (e.g., digest files, hash chaining) gives investigators (and, if needed, courts or auditors) confidence that the evidence is authentic.",{"id":206,"topic":9,"difficulty":207,"body":208,"options":209,"correct_key":157,"explanation":218},"019fab52-a9eb-7151-88e2-9b7f988fa2f7",2,"An organization runs workloads across dozens of AWS accounts. What is the recommended pattern for collecting audit logs so a security team can detect incidents across the whole environment?",[210,212,214,216],{"key":154,"text":211},"Leave each account's logs isolated in that account only, since centralizing logs would violate least-privilege principles.",{"key":157,"text":213},"Aggregate CloudTrail logs from every account into a centralized, access-restricted logging account.",{"key":160,"text":215},"Ask each application team to manually export and email their logs to the security team once a month.",{"key":163,"text":217},"Disable logging in non-production accounts entirely, since incidents only happen in production.","A centralized logging (security\u002Flog-archive) account with restricted write access is the standard multi-account pattern: every account's trail delivers to it, giving the security team a single, tamper-resistant place to search and correlate across the whole organization. Isolating logs per account or skipping non-prod logging creates blind spots.",{"id":220,"topic":9,"difficulty":207,"body":221,"options":222,"correct_key":160,"explanation":231},"019fab52-a9eb-7964-93d4-06fa78978992","What does 'blast radius' mean in the context of a cloud security incident?",[223,225,227,229],{"key":154,"text":224},"The physical distance between the affected data center and the nearest company office.",{"key":157,"text":226},"The total dollar amount of the cloud bill for the month in which the incident occurred.",{"key":160,"text":228},"The scope of resources, permissions, and data that a compromised identity or resource could reach or affect if fully exploited.",{"key":163,"text":230},"The number of support tickets opened by customers after the incident is publicly disclosed.","Blast radius describes how far an attacker could realistically pivot or cause damage from a given foothold — which roles it can assume, which resources it can reach, which data it can read or modify. Limiting blast radius (via scoped permissions, network segmentation) is a core containment goal, independent of billing or PR concerns.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":207,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]