[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fds-security-metrics-blameless-culture":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,82,85,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":73,"name":74,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":76,"name":77,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":79,"name":80,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":8,"name":9,"count":11},{"key":83,"name":84,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":86,"name":87,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,192,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fab8f-ce32-7506-bb69-6141ae392d38",1,"A DevSecOps team tracks Mean Time to Remediate (MTTR) for vulnerabilities found in their pipeline. What does this metric primarily tell the team?",[153,156,159,162],{"key":154,"text":155},"a","How quickly, on average, a discovered vulnerability is fixed and closed after it is first reported.",{"key":157,"text":158},"b","How many total vulnerabilities exist across all repositories regardless of severity or age.",{"key":160,"text":161},"c","Which specific engineer introduced the largest number of vulnerabilities into the codebase.",{"key":163,"text":164},"d","Whether the scanning tool itself is configured correctly and produces zero false positives.","MTTR measures the average time elapsed between a vulnerability's discovery and its remediation, so it reflects how fast the organization responds to known risk, not the total volume of findings or tool accuracy.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":163,"explanation":178},"019fab8f-ce33-705a-ba90-81289989d089","A vulnerability management program defines separate remediation SLAs for critical, high, medium, and low severity findings. Why use tiered SLAs instead of one single deadline for every finding?",[170,172,174,176],{"key":154,"text":171},"Tiered SLAs are required by law in every jurisdiction, so a single deadline would be illegal to enforce.",{"key":157,"text":173},"Tiered SLAs let the security team ignore low-severity findings permanently without any tracking.",{"key":160,"text":175},"Tiered SLAs guarantee that no vulnerability will ever be exploited before its deadline arrives.",{"key":163,"text":177},"Tiered SLAs focus limited remediation effort on the findings that carry the most real risk first.","Severity-based SLAs let teams prioritize scarce engineering time toward the highest-risk findings, giving critical issues the shortest deadlines while lower-risk findings still get tracked on a longer, realistic timeline.",{"id":180,"topic":9,"difficulty":150,"body":181,"options":182,"correct_key":157,"explanation":191},"019fab8f-ce33-7b85-85f1-cd8b497c1faa","What is the core goal of a blameless postmortem after a security incident?",[183,185,187,189],{"key":154,"text":184},"To determine which individual should be formally disciplined or reprimanded for the incident.",{"key":157,"text":186},"To understand the contributing systemic and process factors so similar incidents are less likely to recur.",{"key":160,"text":188},"To keep the details of the incident private from the engineering team so morale is not affected.",{"key":163,"text":190},"To assign a monetary cost to the incident purely for insurance and legal reporting purposes.","A blameless postmortem treats the incident as a signal about systems and processes rather than individual failure, aiming to surface the real contributing factors so the organization can fix them and reduce recurrence.",{"id":193,"topic":9,"difficulty":194,"body":195,"options":196,"correct_key":163,"explanation":205},"019fab8f-ce34-7666-8935-8011a58cb614",2,"During a blameless postmortem, a facilitator asks the team to describe the incident timeline. One participant says: \"It was clearly Ahmet's fault for deploying without a review.\" What is the most appropriate way for the facilitator to redirect this comment?",[197,199,201,203],{"key":154,"text":198},"Agree openly, and add Ahmet's name to the postmortem document as the responsible party.",{"key":157,"text":200},"Ask Ahmet to leave the meeting so the rest of the team can discuss the incident without him.",{"key":160,"text":202},"End the postmortem early, since naming an individual means the process has already failed.",{"key":163,"text":204},"Reframe the discussion toward why the deploy process allowed an unreviewed change to reach production.","A blameless facilitator redirects individual-blame statements toward systemic questions: why did the process allow this to happen, and what guardrail or check was missing, rather than singling out a person.",{"id":207,"topic":9,"difficulty":150,"body":208,"options":209,"correct_key":160,"explanation":218},"019fab8f-ce35-717e-ba90-55cb74fe9abe","In a security champion program, what is a security champion?",[210,212,214,216],{"key":154,"text":211},"A dedicated full-time security engineer embedded permanently inside every product team's headcount, separate from any existing engineering role.",{"key":157,"text":213},"An external auditor hired once a year to certify the team's compliance with a specific standard.",{"key":160,"text":215},"A developer on a product team who receives extra security training and acts as a local point of contact.",{"key":163,"text":217},"A software tool that automatically blocks any pull request containing a detected vulnerability.","A security champion is typically a developer already on the team, given extra training and a liaison role with the central security function, not a separate headcount, external auditor, or automated tool.",{"id":220,"topic":9,"difficulty":194,"body":221,"options":222,"correct_key":154,"explanation":231},"019fab8f-ce35-77f4-970a-80372eaba4fe","A company wants a basic way to gauge whether its security champion program is actually working. Which measurement gives the most direct signal?",[223,225,227,229],{"key":154,"text":224},"Comparing security-relevant defect rates and review turnaround in teams with an active champion versus those without.",{"key":157,"text":226},"Counting how many champions attended the kickoff meeting when the program was first announced.",{"key":160,"text":228},"Checking whether every champion has the exact same job title printed on the company directory.",{"key":163,"text":230},"Measuring how many stickers or badges were printed for champions during the program launch.","A meaningful signal compares outcomes, such as security defect rates or review speed, between teams with and without an active champion, rather than superficial attendance or branding metrics.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":194,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]