[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fsecurity-cloud-infra-security":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","security-cloud-infra-security","Security Cloud Infra Security","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,87,90,93,96,99,102,105,108,111,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":73,"name":74,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":76,"name":77,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":79,"name":80,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":82,"name":83,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":85,"name":86,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":88,"name":89,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":91,"name":92,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":94,"name":95,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":97,"name":98,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":100,"name":101,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":103,"name":104,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":106,"name":107,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":109,"name":110,"count":11},"security-authn-authz","Security Authn Authz",{"key":8,"name":9,"count":11},{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,180,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":160,"explanation":165},"019f686c-5941-7d29-a346-7e89c2715b17",1,"What does the principle of \"least privilege\" mean in access management?",[153,156,159,162],{"key":154,"text":155},"a","Granting broad permissions by default and restricting them only if abuse occurs.",{"key":157,"text":158},"b","Giving every user administrator-level access to simplify support and troubleshooting.",{"key":160,"text":161},"c","Only the permissions needed for its task, nothing more.",{"key":163,"text":164},"d","Allowing permissions to accumulate over time as a convenience for busy teams.","Least privilege means granting an identity only the access it actually needs; any extra permission simply enlarges the blast radius an attacker gains if that identity is compromised.",{"id":167,"topic":9,"difficulty":168,"body":169,"options":170,"correct_key":154,"explanation":179},"019f686c-5942-749a-bd5b-9d4114d1862f",2,"A batch job only needs to read files from one storage location and write logs to another. Which access setup best follows least privilege?",[171,173,175,177],{"key":154,"text":172},"A dedicated identity limited to read there and write only on the log destination.",{"key":157,"text":174},"Reuse the administrator identity already configured on the server.",{"key":160,"text":176},"Grant read\u002Fwrite access to all storage locations in the account for flexibility.",{"key":163,"text":178},"Grant the job owner's personal account permissions to the batch process.","A dedicated, narrowly scoped identity for the job improves traceability and, if that identity is compromised, limits the impact to only the resources it was meant to touch; reusing an administrator or personal account creates unnecessarily broad access.",{"id":181,"topic":9,"difficulty":168,"body":182,"options":183,"correct_key":163,"explanation":192},"019f686c-5942-7e38-a29a-7e396e63c2d5","A team gave a new intern account full administrative access \"just to be safe\" while the intern learns the systems. What is the main risk of this decision?",[184,186,188,190],{"key":154,"text":185},"The intern's account will automatically expire faster than a limited account.",{"key":157,"text":187},"Administrative accounts are audited less often than limited accounts.",{"key":160,"text":189},"Full access accounts perform tasks more slowly due to extra permission checks.",{"key":163,"text":191},"It can affect far more systems than the intern's job actually requires.","If the actual task only requires narrow access, granting broad privileges only increases the potential damage from a mistake or a compromise; \"just to be safe\" produces the opposite of safety.",{"id":194,"topic":9,"difficulty":150,"body":195,"options":196,"correct_key":157,"explanation":205},"019f686c-5943-74d6-85ba-7e1c7316e5fb","In the shared responsibility model for cloud services, which statement is generally correct?",[197,199,201,203],{"key":154,"text":198},"The provider is fully responsible for the security of everything running in the customer's account.",{"key":157,"text":200},"The provider secures the infrastructure; the customer secures what it configures on top.",{"key":160,"text":202},"The customer is responsible for the physical security of the data centers.",{"key":163,"text":204},"Responsibility is split evenly and does not depend on which service model is used.","The shared responsibility model is not a fixed line: the provider secures the underlying layers (hardware, network, and sometimes the operating system), while the customer remains responsible for the access, data, and application layers it configures on top.",{"id":207,"topic":9,"difficulty":168,"body":208,"options":209,"correct_key":154,"explanation":218},"019f686c-5943-7bbc-80d7-aebd8f8657c0","A company deploys an application on a fully managed platform where the provider handles the runtime and operating system. Who is still responsible for securing the application's own configuration and access controls?",[210,212,214,216],{"key":154,"text":211},"The customer, since infrastructure duty differs from application duty.",{"key":157,"text":213},"The provider, since managed platforms take over all security decisions by design.",{"key":160,"text":215},"Neither party, since managed platforms are certified secure by default.",{"key":163,"text":217},"Only the provider's support team, once a support contract is signed.","Even though a managed platform takes on the infrastructure layer, decisions like the application's access controls, authentication flow, and data configuration remain the customer's responsibility.",{"id":220,"topic":9,"difficulty":168,"body":221,"options":222,"correct_key":160,"explanation":231},"019f686c-5944-77e1-b933-ba27beda4168","Why does the responsibility split in the shared responsibility model change depending on whether infrastructure, a platform, or ready-to-use software is delivered as a service?",[223,225,227,229],{"key":154,"text":224},"The split does not actually change; it is only a marketing distinction between service types.",{"key":157,"text":226},"The split changes based only on the price the customer pays for the service.",{"key":160,"text":228},"Each model shifts a different layer of the stack into the provider's control.",{"key":163,"text":230},"The split is decided case-by-case by the customer's legal department, not by architecture.","Infrastructure, platform, and software service models each shift a different layer of the stack to the provider; consequently, the layers the customer still has to secure differ depending on the model.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":168,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]