[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fpt-legal-ethical-boundaries":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,87,90,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":73,"name":74,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":76,"name":77,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":79,"name":80,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":82,"name":83,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":85,"name":86,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":88,"name":89,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":8,"name":9,"count":11},{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fadba-fe9e-78ac-ace9-9c18ef2c814a",1,"Before a pentester runs any tool against a client's systems, what must exist to make that testing legally authorized rather than unauthorized computer access?",[153,156,159,162],{"key":154,"text":155},"a","A signed authorization document from someone with legal authority over those systems.",{"key":157,"text":158},"b","A verbal promise from a developer that the tester met once at a conference.",{"key":160,"text":161},"c","A public news article mentioning that the client company has weak security.",{"key":163,"text":164},"d","The tester's own belief that the systems look interesting and probably want to be tested.","Authorization must come from a party with actual legal authority over the target systems, documented in writing (an authorization letter or signed contract). Without it, even well-intentioned testing is unauthorized access.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":163,"explanation":178},"019fadba-feaa-7da5-a2bb-738e48574f57","What is the primary purpose of a Rules of Engagement (RoE) document in a pentest engagement?",[170,172,174,176],{"key":154,"text":171},"It replaces the need for any technical report at the end of the engagement.",{"key":157,"text":173},"It is a marketing document used to advertise the testing firm's services.",{"key":160,"text":175},"It is only relevant for red team engagements involving multi-week no-notice testing and is never used in a standard, short pentest.",{"key":163,"text":177},"It defines the boundaries, timing, and contacts for the test so both sides share the same expectations.","The RoE spells out what is in scope, testing windows, allowed techniques, and emergency contacts, giving both the client and tester a shared, agreed-upon boundary for the work.",{"id":180,"topic":9,"difficulty":181,"body":182,"options":183,"correct_key":157,"explanation":192},"019fadba-feac-7037-87cb-b2743d56193d",2,"During a network scan, a tester notices a server that appears to belong to a completely different company than the client, reachable through a misconfigured shared network segment. What should the tester do?",[184,186,188,190],{"key":154,"text":185},"Continue scanning it and enumerate its running services in detail, since it was reachable from the client's network by accident.",{"key":157,"text":187},"Stop interacting with that server, note the discovery, and report it to the client without probing it further.",{"key":160,"text":189},"Quietly ignore it and leave it out of the final report entirely.",{"key":163,"text":191},"Attempt to identify who owns it by actively enumerating its services in detail.","A system outside the authorized scope is off-limits, even if it was reached accidentally. The correct move is to stop, document the discovery, and inform the client — continuing to probe an unauthorized third-party system risks legal exposure for both the tester and the client.",{"id":194,"topic":9,"difficulty":150,"body":195,"options":196,"correct_key":154,"explanation":205},"019fadba-feae-7adb-8c24-2c096fcf0f4d","What does 'scope' mean in the context of a pentest engagement?",[197,199,201,203],{"key":154,"text":198},"The specific systems, networks, or applications that are authorized to be tested.",{"key":157,"text":200},"The total price the client agreed to pay for the engagement.",{"key":160,"text":202},"The brand of tools the testing team plans to use during the assessment.",{"key":163,"text":204},"The number of testers the firm assigns to staff the engagement from start to finish.","Scope defines exactly which assets (IP ranges, domains, applications) are covered by the authorization. Anything outside that definition is not authorized, regardless of how the test is staffed, priced, or tooled.",{"id":207,"topic":9,"difficulty":181,"body":208,"options":209,"correct_key":157,"explanation":218},"019fadba-feaf-7a0b-8520-982e0dd0c68b","A pentester is testing a web application and, while exploring a normal feature, stumbles onto a database export containing real customer names and payment details that was clearly not meant to be exposed. What is the appropriate immediate handling of this discovery?",[210,212,214,216],{"key":154,"text":211},"Download the full export locally to keep as a personal proof-of-concept sample for future reference.",{"key":157,"text":213},"Record only enough detail to prove the finding, avoid extracting or storing the sensitive data itself, and report it promptly.",{"key":160,"text":215},"Share the sample data with colleagues at other companies to warn them about similar risks.",{"key":163,"text":217},"Ignore it and continue testing other features, since accidental discoveries are assumed to fall outside any reporting duty.","Handling sensitive data discovered during a test requires minimizing exposure: capture only what is needed to demonstrate the finding (e.g., a redacted screenshot or record count), avoid bulk extraction or unnecessary storage, and escalate promptly — this respects data-protection obligations toward people who never consented to being part of the test.",{"id":220,"topic":9,"difficulty":150,"body":221,"options":222,"correct_key":163,"explanation":231},"019fadba-feb4-7973-8790-e64a4b4b20ce","In the context of vulnerability disclosure, what does 'responsible disclosure' generally mean?",[223,225,227,229],{"key":154,"text":224},"Selling the details of the finding to the highest bidder instead of contacting the vendor.",{"key":157,"text":226},"Publishing full technical details on social media the moment it is found, before the vendor even acknowledges the report.",{"key":160,"text":228},"Waiting indefinitely, sometimes years, without ever telling the vendor anything about the finding.",{"key":163,"text":230},"Privately notifying the affected vendor first and giving them reasonable time to fix the issue before any public details are shared.","Responsible (or coordinated) disclosure means informing the affected party privately first, allowing a reasonable remediation window, and only sharing broader details afterward, typically in coordination with the vendor's own timeline.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":181,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]