[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fds-iac-policy-as-code":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","ds-iac-policy-as-code","Ds Iac Policy As Code","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":8,"name":9,"count":11},{"key":74,"name":75,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":77,"name":78,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":80,"name":81,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fab8f-cde3-7bb1-af7e-dca19fb10c8c",1,"What is the main purpose of running a static IaC scanner (e.g. Checkov, tfsec) against Terraform files as part of a pipeline?",[153,156,159,162],{"key":154,"text":155},"a","To detect misconfigurations in the infrastructure definition before it is ever provisioned.",{"key":157,"text":158},"b","To automatically format the Terraform code according to the team's style guide.",{"key":160,"text":161},"c","To reduce the cloud bill by predicting the monthly cost of the planned resources.",{"key":163,"text":164},"d","To replace the need for a code reviewer to look at the pull request at all, since an automated scanner is assumed to catch every issue a human reviewer normally would.","Static IaC scanners parse the Terraform\u002FCloudFormation source and check it against a set of security and compliance rules, so problems like an unencrypted bucket or an open security group are caught while the change is still just text, before any real resource is created.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":163,"explanation":178},"019fab8f-cdea-7b0c-9d51-fd860b497033","In the policy-as-code ecosystem, what is Open Policy Agent (OPA) best described as?",[170,172,174,176],{"key":154,"text":171},"A secrets manager that issues short-lived credentials to CI\u002FCD runners, positioned as an alternative to storing long-lived static credentials in pipeline configuration.",{"key":157,"text":173},"A Terraform provider that creates cloud resources directly from Rego files.",{"key":160,"text":175},"A vulnerability scanner that inspects container images for known CVEs.",{"key":163,"text":177},"A general-purpose policy engine that evaluates structured input against rules and returns an allow\u002Fdeny decision.","OPA is a general-purpose policy engine: you feed it structured input (JSON) plus policies written in Rego, and it evaluates the input against those policies to produce a decision, independent of what kind of system is asking the question.",{"id":180,"topic":9,"difficulty":181,"body":182,"options":183,"correct_key":157,"explanation":192},"019fab8f-cdec-7760-bd59-c9279d4d7679",2,"What is Rego, in the context of OPA?",[184,186,188,190],{"key":154,"text":185},"A binary format used to compress Terraform state files before upload to remote backends.",{"key":157,"text":187},"A declarative query language used to write the policy rules that OPA evaluates.",{"key":160,"text":189},"A CLI flag that forces terraform apply to skip the plan confirmation step.",{"key":163,"text":191},"A CloudFormation intrinsic function used to reference stack parameters.","Rego is OPA's declarative policy language: rules are written as queries over the input document, and OPA evaluates them to decide whether a given input satisfies the policy.",{"id":194,"topic":9,"difficulty":181,"body":195,"options":196,"correct_key":154,"explanation":205},"019fab8f-cded-7874-8ad8-ddd450c67ae3","What does Conftest primarily do in a pipeline that checks Terraform or Kubernetes manifests?",[197,199,201,203],{"key":154,"text":198},"It runs OPA\u002FRego policies against structured configuration files and reports pass\u002Ffail results.",{"key":157,"text":200},"It signs the manifest files with a GPG key so their origin and integrity can be verified later by anyone consuming the artifact downstream.",{"key":160,"text":202},"It automatically rewrites non-compliant fields in the manifest to compliant values.",{"key":163,"text":204},"It provisions a temporary staging environment to test the manifests before merge.","Conftest is a thin wrapper around OPA aimed at structured config files: it loads Rego policies and runs them against inputs such as a `terraform plan` JSON export or Kubernetes YAML, reporting which policies passed or failed.",{"id":207,"topic":9,"difficulty":181,"body":208,"options":209,"correct_key":157,"explanation":218},"019fab8f-cdef-7070-a3ec-0a5add4aae6b","A team wants every pull request that adds an S3 bucket to be blocked automatically unless the bucket definition includes a server-side encryption block. Which approach fits this requirement?",[210,212,214,216],{"key":154,"text":211},"Ask reviewers to manually search each diff for the word \"encryption\" before approving.",{"key":157,"text":213},"Add a policy-as-code rule that checks for the encryption block and fail the pipeline stage when it is missing.",{"key":160,"text":215},"Enable encryption on the bucket after deployment through the cloud console.",{"key":163,"text":217},"Document the encryption requirement in the team wiki and trust developers to remember and follow it consistently across every future change.","A policy-as-code rule evaluated in the pipeline turns the requirement into an automated, repeatable gate: any PR whose Terraform diff is missing the encryption block fails the check, instead of relying on manual review or after-the-fact fixes.",{"id":220,"topic":9,"difficulty":150,"body":221,"options":222,"correct_key":163,"explanation":231},"019fab8f-cdf0-75f1-a055-cdd64ddf7989","Which statement best defines \"policy as code\" in a DevSecOps pipeline?",[223,225,227,229],{"key":154,"text":224},"A manual checklist that a security reviewer fills in by hand for every release, based on their personal experience and judgment at that time.",{"key":157,"text":226},"Every security policy is stored as a PDF attached to the ticket that introduced it.",{"key":160,"text":228},"Developers write their own ad-hoc security checks inside application business logic.",{"key":163,"text":230},"Security and compliance rules are expressed as version-controlled, machine-evaluable code rather than as prose documents.","Policy as code means the rule itself (e.g. \"encryption must be enabled\") is written in a language a tool can parse and evaluate automatically, and that rule lives in version control alongside the infrastructure it governs, rather than in a document a human has to remember to check.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":181,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]