[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fsecurity-compliance-risk":4,"config":233},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","security-compliance-risk","Security Compliance Risk","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,87,90,93,96,99,102,105,108,111,114,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":73,"name":74,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":76,"name":77,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":79,"name":80,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":82,"name":83,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":85,"name":86,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":88,"name":89,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":91,"name":92,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":94,"name":95,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":97,"name":98,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":100,"name":101,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":103,"name":104,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":106,"name":107,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":109,"name":110,"count":11},"security-authn-authz","Security Authn Authz",{"key":112,"name":113,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":8,"name":9,"count":11},{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,180,194,207,220],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019f686c-5954-78eb-aaed-97de67f3a4c1",2,"A team scores security risks using risk_score = likelihood (1-5) × impact (1-5). Vulnerability A has likelihood 2 and impact 5. Vulnerability B has likelihood 5 and impact 2. Both compute to a risk_score of 10. What is the correct interpretation of this equal score?",[153,156,159,162],{"key":154,"text":155},"a","The equal score hides different risk profiles — A is rare-but-severe, B is frequent-but-minor — so treatment should track the driving factor.",{"key":157,"text":158},"b","Both carry the identical numeric score, so they can safely be handed the same mitigation plan without looking at which factor produced the number.",{"key":160,"text":161},"c","The equal score means both findings should be assigned to the same on-call team, since the score alone determines ownership routing.",{"key":163,"text":164},"d","Multiplying likelihood by impact is invalid whenever the two individual factors differ between findings, even if the product happens to match.","A risk score is a comparison aid, not a full description of the risk. Two findings can land on the same number for very different reasons — one driven by severe-but-rare impact, the other by frequent-but-minor impact — and those reasons should shape which control (e.g., hardening a rare failure path vs. rate-limiting a frequent one) gets prioritized.",{"id":167,"topic":9,"difficulty":168,"body":169,"options":170,"correct_key":157,"explanation":179},"019f686c-5955-7c4c-8df0-5972c6465a6d",1,"What does 'risk' mean conceptually in a security context?",[171,173,175,177],{"key":154,"text":172},"The certainty that a specific attack will occur against the system at some point in the future.",{"key":157,"text":174},"The potential for loss when a threat exploits a vulnerability, generally weighed by likelihood and impact together.",{"key":160,"text":176},"Any deviation from an internal company policy document, regardless of whether it enables actual harm.",{"key":163,"text":178},"The purchase cost of the security tooling a team has chosen to deploy across its systems.","Risk is not certainty of harm, nor is it simply a policy deviation or a tool's price tag. It is the potential for loss when a threat exploits a vulnerability, and it is meaningfully described by combining how likely that is with how bad the outcome would be.",{"id":181,"topic":9,"difficulty":182,"body":183,"options":184,"correct_key":160,"explanation":193},"019f686c-5956-7713-abec-af1088eaa2f0",3,"A team places findings on a likelihood\u002Fimpact matrix. One finding is low-likelihood, high-impact — a rare but catastrophic failure of the backup-restore process. Another is high-likelihood, low-impact — frequent failed logins with no meaningful downstream consequence. How should the team compare these two when deciding priority?",[185,187,189,191],{"key":154,"text":186},"The high-likelihood, low-impact finding should always be handled first, since anything that happens often automatically outranks anything rare.",{"key":157,"text":188},"The low-likelihood, high-impact finding can be dropped from the backlog entirely, since rare events are not worth planning for.",{"key":160,"text":190},"Both need context-specific evaluation — a rare catastrophic risk can outrank a frequent minor one, so likelihood alone shouldn't decide.",{"key":163,"text":192},"Impact should be ignored whenever likelihood is low, because a low likelihood factor dominates the overall ranking by itself.","A likelihood\u002Fimpact matrix is meant to surface trade-offs, not to let one axis auto-decide the answer. A rare event that could be catastrophic (e.g., an unrecoverable backup failure) can reasonably outrank a frequent but low-consequence nuisance, so both dimensions need to be weighed together rather than picking a winner from one axis alone.",{"id":195,"topic":9,"difficulty":150,"body":196,"options":197,"correct_key":163,"explanation":206},"019f686c-5957-7175-b52e-e40f54c55b71","An organization identifies a risk and formally decides to add no additional control, documenting the decision along with a named residual-risk owner. Which risk treatment category does this represent, and how does it differ from mitigation?",[198,200,202,204],{"key":154,"text":199},"Mitigation — because writing down the decision itself is a control that reduces the impact of the underlying risk.",{"key":157,"text":201},"Avoidance — because documenting the decision removes the activity that was the source of the risk in the first place.",{"key":160,"text":203},"Transfer — because putting the decision in writing shifts responsibility for the outcome onto whoever signs the document.",{"key":163,"text":205},"Acceptance — the risk is knowingly retained without reducing likelihood or impact, unlike mitigation.","Documenting a decision to take no further action, with an accountable owner, is the definition of risk acceptance: the risk is knowingly retained as-is. Mitigation, by contrast, actively reduces likelihood or impact through additional controls — the two are distinct even though both can be legitimate outcomes of a risk assessment.",{"id":208,"topic":9,"difficulty":150,"body":209,"options":210,"correct_key":154,"explanation":219},"019f686c-5957-7c13-b197-632b00a20e07","A company depends on a legacy internal tool with a known vulnerability that cannot be patched in the near term. Instead of fixing it, the company purchases a cyber-insurance policy covering losses from a breach of that specific tool. Which risk treatment category best describes this action?",[211,213,215,217],{"key":154,"text":212},"Transfer — the financial consequence shifts to a third party while the vulnerability itself remains unchanged.",{"key":157,"text":214},"Mitigation — because paying a premium reduces the technical likelihood that the vulnerability will ever be exploited.",{"key":160,"text":216},"Avoidance — because insurance removes the activity that created the vulnerability from the system entirely.",{"key":163,"text":218},"Acceptance — because the company has decided the vulnerability is not worth budgeting anything toward addressing.","Buying insurance does not change the vulnerability's likelihood or eliminate the activity — the tool remains exploitable exactly as before. What changes is who bears the financial consequence if it is exploited, which is the defining trait of risk transfer, distinct from mitigation, avoidance, or acceptance.",{"id":221,"topic":9,"difficulty":168,"body":222,"options":223,"correct_key":157,"explanation":232},"019f686c-5958-745f-aaf7-127e23b0c62c","Which action is the clearest example of risk avoidance?",[224,226,228,230],{"key":154,"text":225},"Purchasing insurance that pays out in the event of a data breach affecting customer records.",{"key":157,"text":227},"Discontinuing the feature entirely, since that removes the underlying risk source altogether.",{"key":160,"text":229},"Adding a network firewall rule that reduces the exposure of an internal service.",{"key":163,"text":231},"Formally documenting and accepting a known low-severity risk that remains in the system.","Avoidance means eliminating the activity that creates the risk in the first place — here, dropping the feature removes the risk source entirely. Insurance is transfer, a firewall rule is mitigation, and documenting acceptance is acceptance — each is a distinct treatment category.",{"fields":234,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[235,260,280,296,320,333,352,371,381,388,394,401],{"key":236,"name_tr":237,"name_en":237,"sort":168,"specializations":238},"backend","Backend",[239,242,245,248,251,254,257],{"key":240,"name":241,"field":236},"general","Genel",{"key":243,"name":244,"field":236},"go","Go",{"key":246,"name":247,"field":236},"python","Python",{"key":249,"name":250,"field":236},"java","Java",{"key":252,"name":253,"field":236},"csharp","C#\u002F.NET",{"key":255,"name":256,"field":236},"nodejs","Node.js",{"key":258,"name":259,"field":236},"php","PHP",{"key":261,"name_tr":262,"name_en":262,"sort":150,"specializations":263},"frontend","Frontend",[264,265,268,271,274,277],{"key":240,"name":241,"field":261},{"key":266,"name":267,"field":261},"javascript","JavaScript",{"key":269,"name":270,"field":261},"typescript","TypeScript",{"key":272,"name":273,"field":261},"react","React",{"key":275,"name":276,"field":261},"vue","Vue",{"key":278,"name":279,"field":261},"angular","Angular",{"key":281,"name_tr":282,"name_en":282,"sort":182,"specializations":283},"fullstack","Fullstack",[284,285,286,287,288,289,290,291,292,293,294,295],{"key":240,"name":241,"field":281},{"key":243,"name":244,"field":236},{"key":246,"name":247,"field":236},{"key":249,"name":250,"field":236},{"key":252,"name":253,"field":236},{"key":255,"name":256,"field":236},{"key":258,"name":259,"field":236},{"key":266,"name":267,"field":261},{"key":269,"name":270,"field":261},{"key":272,"name":273,"field":261},{"key":275,"name":276,"field":261},{"key":278,"name":279,"field":261},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":240,"name":241,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":240,"name":241,"field":321},{"key":246,"name":247,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":240,"name":241,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":240,"name":241,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":240,"name":241,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":240,"name":241,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":240,"name":241,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":240,"name":241,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":240,"name":241,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]