[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fcse-iam-privilege-escalation":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","cse-iam-privilege-escalation","Cse Iam Privilege Escalation","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":8,"name":9,"count":11},{"key":68,"name":69,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,180,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fab52-a9fe-7dd0-b7b9-214ff2f81a1e",1,"From a cloud security analyst's perspective, what does \"IAM privilege escalation\" mean?",[153,156,159,162],{"key":154,"text":155},"a","An identity uses the permissions it already has to obtain additional permissions or access it was not meant to have",{"key":157,"text":158},"b","A user's password expires and they must reset it before logging in again",{"key":160,"text":161},"c","A cloud provider increases the CPU quota available to an account",{"key":163,"text":164},"d","An administrator manually reviews and approves every access request before it is granted","Privilege escalation in IAM is not about brute-forcing a login — it is an identity (user, role, or service account) leveraging permissions it already legitimately holds to grant itself, or reach, permissions beyond its intended scope.",{"id":167,"topic":9,"difficulty":168,"body":169,"options":170,"correct_key":163,"explanation":179},"019fab52-a9ff-76ee-a46c-ba9d5a7f9e26",2,"A cloud role has both `iam:PassRole` and `lambda:CreateFunction` permissions, but no permission to directly assume any other role. Why does a security analyst still flag this combination as risky?",[171,173,175,177],{"key":154,"text":172},"PassRole and CreateFunction belong to unrelated services and cannot be combined in any attack chain",{"key":157,"text":174},"Lambda functions cannot use execution roles at all, so this combination is actually harmless. Lambda's execution model always discards any role reference at deploy time and substitutes the account's default anonymous execution context instead.",{"key":160,"text":176},"This combination only matters if the identity also has console (UI) access enabled",{"key":163,"text":178},"The identity can create a Lambda function, attach a highly privileged execution role to it via PassRole, and then trigger code that runs with that role's permissions","This is a canonical privilege-escalation chain: PassRole alone does not grant new permissions, but paired with the ability to create a compute resource (a Lambda function) that executes with a passed role, the identity effectively gains everything that target role can do, without ever needing sts:AssumeRole on it directly.",{"id":181,"topic":9,"difficulty":150,"body":182,"options":183,"correct_key":157,"explanation":192},"019fab52-aa00-72bb-8aa3-2a43e667aa37","What is a \"cross-account trust policy\" in the context of cloud IAM?",[184,186,188,190],{"key":154,"text":185},"A document listing which employees are trusted to have physical access to a data center",{"key":157,"text":187},"A policy attached to a role in one account that specifies which principals from other accounts are allowed to assume that role",{"key":160,"text":189},"A password policy that applies across every account in an organization",{"key":163,"text":191},"A billing agreement between a cloud provider and a customer organization","A cross-account trust policy defines who (which external account, role, or federated identity) is permitted to assume a role, effectively bridging trust boundaries between separate cloud accounts.",{"id":194,"topic":9,"difficulty":150,"body":195,"options":196,"correct_key":154,"explanation":205},"019fab52-aa00-7a6e-a589-24d16c00e327","What is identity federation in a cloud IAM context?",[197,199,201,203],{"key":154,"text":198},"Allowing an external identity provider (such as a corporate directory, OIDC provider, or SAML IdP) to authenticate users who then receive temporary access to cloud resources",{"key":157,"text":200},"Encrypting all IAM policy documents with a shared organizational key. This design choice is standard practice specifically because federation providers are assumed to already perform authorization checks equivalent to the cloud provider's own IAM evaluation.",{"key":160,"text":202},"Combining multiple cloud provider accounts into a single billing statement",{"key":163,"text":204},"Requiring every user to have a separate native account in each cloud provider they use","Federation lets an organization trust an external identity provider for authentication, so users (or workloads) sign in once and receive short-lived, mapped access to the cloud environment instead of maintaining a separate native identity there.",{"id":207,"topic":9,"difficulty":168,"body":208,"options":209,"correct_key":157,"explanation":218},"019fab52-aa01-7214-b654-31be2c250bdd","Why do security analysts specifically flag wildcard actions like `\"Action\": \"iam:*\"` in a policy attached to a workload identity, even one that is not itself a human admin?",[210,212,214,216],{"key":154,"text":211},"Wildcard actions are only a performance concern because policy evaluation takes longer. Cloud providers measure this cost strictly in milliseconds of policy-evaluation latency and log it separately from any access-control telemetry.",{"key":157,"text":213},"It grants the identity the ability to modify IAM itself, including potentially attaching admin policies to itself or other roles, turning any compromise of that workload into a full account takeover",{"key":160,"text":215},"Wildcard actions are purely a cosmetic style issue with no security implication",{"key":163,"text":217},"IAM wildcards are automatically restricted by the cloud provider to read-only operations","A workload identity with unrestricted `iam:*` can rewrite trust policies, attach new permissions, or create new privileged identities — meaning compromising that single, possibly low-value workload gives an attacker a path to full administrative control.",{"id":220,"topic":9,"difficulty":168,"body":221,"options":222,"correct_key":160,"explanation":231},"019fab52-aa01-7945-b3c3-68ed11310968","In most cloud IAM policy evaluation logics, what happens when one attached policy explicitly allows an action and another explicitly denies the same action for the same identity?",[223,225,227,229],{"key":154,"text":224},"The allow always wins because allows are evaluated first",{"key":157,"text":226},"The two policies cancel out and the action is neither allowed nor denied, defaulting to allow",{"key":160,"text":228},"The explicit deny wins over the explicit allow, so the action is blocked",{"key":163,"text":230},"The cloud provider prompts an administrator to manually resolve the conflict","A foundational rule an analyst must know when auditing policies: an explicit deny takes precedence over any allow, anywhere in the evaluated policy set — this is exactly why a single well-placed deny (e.g. in an SCP or boundary) can act as a hard guardrail against escalation.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":168,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]