[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fcse-network-perimeter-zero-trust":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":8,"name":9,"count":11},{"key":71,"name":72,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,192,205,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":163,"explanation":165},"019fab52-aa13-73bf-afd6-f5dbc375d13a",1,"A cloud security analyst reviews a security group rule allowing inbound TCP port 22 from 0.0.0.0\u002F0. What is the primary risk this represents?",[153,156,159,162],{"key":154,"text":155},"a","It slows down SSH handshake performance for legitimate users",{"key":157,"text":158},"b","It automatically disables encryption for the SSH session",{"key":160,"text":161},"c","It forces the instance to use an outdated SSH protocol version instead of negotiating the strongest algorithm the client supports",{"key":163,"text":164},"d","Any host on the internet can attempt SSH connections to the instance","0.0.0.0\u002F0 means the rule matches every IPv4 source address, so any internet host can attempt to reach port 22. This dramatically increases exposure to brute-force and credential-stuffing attempts. It has no effect on handshake speed, protocol version, or encryption.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":157,"explanation":178},"019fab52-aa13-7bcd-9fb8-1462d38c9fc7","What is the key architectural difference between a security group and a network ACL (NACL) in most cloud VPC designs?",[170,172,174,176],{"key":154,"text":171},"Security groups operate only at Layer 2, NACLs at Layer 3",{"key":157,"text":173},"Security groups are stateful (return traffic is auto-allowed), NACLs are typically stateless",{"key":160,"text":175},"NACLs can only allow traffic, security groups can only deny traffic",{"key":163,"text":177},"Security groups apply to entire VPCs and cannot be attached to individual instances, while NACLs apply only to single instances and ignore subnet boundaries","Security groups are stateful: if inbound traffic is allowed, the corresponding return traffic is automatically permitted. NACLs operate at the subnet level and are typically stateless, requiring explicit rules for both directions. Both work above Layer 2, and both support allow and deny semantics (NACLs) or allow-only (security groups).",{"id":180,"topic":9,"difficulty":150,"body":181,"options":182,"correct_key":163,"explanation":191},"019fab52-aa14-7456-916b-4e6b298b24f8","In zero-trust network access (ZTNA), what replaces the traditional assumption that traffic inside the corporate perimeter is trusted?",[183,185,187,189],{"key":154,"text":184},"VPN concentrators become unnecessary and are removed entirely",{"key":157,"text":186},"All internal traffic is left unencrypted since it never leaves the data center, on the assumption that anything already inside the building is inherently safe",{"key":160,"text":188},"Only the outermost firewall performs any access control decisions",{"key":163,"text":190},"Every access request is authenticated and authorized regardless of network location","ZTNA's core principle is 'never trust, always verify': every request is authenticated and authorized based on identity, device posture, and context, regardless of whether it originates inside or outside the traditional perimeter. It does not mean leaving traffic unencrypted or centralizing all decisions at one firewall.",{"id":193,"topic":9,"difficulty":150,"body":194,"options":195,"correct_key":154,"explanation":204},"019fab52-aa14-7bc5-94d7-086dee2f5860","Why is 'lateral movement' a concern that a flat, unsegmented network makes worse?",[196,198,200,202],{"key":154,"text":197},"A compromised host can reach many other systems without crossing an inspection or policy boundary",{"key":157,"text":199},"It increases the monthly cost of data transfer between regions",{"key":160,"text":201},"It prevents load balancers from performing health checks correctly, causing healthy backend instances to be marked as unavailable",{"key":163,"text":203},"It makes DNS resolution slower across subnets","In a flat network, once an attacker compromises one host, they can typically reach many other systems directly since there are few or no segmentation boundaries (firewalls, microsegmentation policies) to cross. This has no direct relation to DNS speed, cross-region cost, or load balancer health checks.",{"id":206,"topic":9,"difficulty":207,"body":208,"options":209,"correct_key":157,"explanation":218},"019fab52-aa15-72b7-b061-b39b47006da1",2,"A security analyst finds a database subnet's NACL that allows all inbound traffic on all ports from the application subnet's CIDR range. What is the main concern with this configuration?",[210,212,214,216],{"key":154,"text":211},"NACLs cannot reference CIDR ranges, so the rule is invalid and has no effect",{"key":157,"text":213},"Any port on any host in the application subnet can reach the database, not just the specific ports the application actually needs",{"key":160,"text":215},"This configuration will cause the database to reject all legitimate connections, since NACLs that allow a range are treated as conflicting deny rules by the platform",{"key":163,"text":217},"NACL rules referencing CIDR ranges automatically expire after 24 hours","Allowing all ports from an entire subnet CIDR violates least privilege: if any single host in the application subnet is compromised, or if a misconfigured service listens on an unexpected port, it gains broad reachability to the database. The rule is syntactically valid, does not block legitimate traffic, and NACL rules do not expire automatically.",{"id":220,"topic":9,"difficulty":207,"body":221,"options":222,"correct_key":154,"explanation":231},"019fab52-aa15-79b8-ae90-4ace6a323ed2","What security benefit does a private endpoint (or PrivateLink-style connection) provide when an application accesses a managed cloud service such as object storage?",[223,225,227,229],{"key":154,"text":224},"Traffic stays on the cloud provider's private network instead of traversing the public internet",{"key":157,"text":226},"It removes the need for any authentication to the managed service",{"key":160,"text":228},"It automatically encrypts data at rest with a customer-managed key, removing the need to configure any key management service separately",{"key":163,"text":230},"It guarantees the managed service will have zero downtime","Private endpoints route traffic through the provider's private backbone rather than the public internet, reducing exposure to internet-based interception or exfiltration paths and allowing tighter network-level access control. It does not remove authentication requirements, does not automatically manage encryption keys, and has no bearing on service uptime guarantees.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":207,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]