[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fsecurity-incident-response":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","security-incident-response","Security Incident Response","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,87,90,93,96,99,102,105,108,111,114,117,120,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":73,"name":74,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":76,"name":77,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":79,"name":80,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":82,"name":83,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":85,"name":86,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":88,"name":89,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":91,"name":92,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":94,"name":95,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":97,"name":98,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":100,"name":101,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":103,"name":104,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":106,"name":107,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":109,"name":110,"count":11},"security-authn-authz","Security Authn Authz",{"key":112,"name":113,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":115,"name":116,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":118,"name":119,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":8,"name":9,"count":11},{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019f686c-597a-789a-9d28-a3f128379158",1,"A security team writes and rehearses an incident response plan long before any real incident happens. What is the main reason for doing this preparation work in advance?",[153,156,159,162],{"key":154,"text":155},"a","It sets roles and escalation paths in advance, so responders act fast and consistently under pressure.",{"key":157,"text":158},"b","It guarantees that no security incident will ever happen again once the plan is approved by management.",{"key":160,"text":161},"c","It replaces the need for monitoring or logging, since a written plan alone can detect intrusions.",{"key":163,"text":164},"d","It exists only to satisfy an annual audit checklist and has little effect on how a real incident unfolds.","Preparation is a distinct phase of incident response: defining roles, contacts, and decision authority ahead of time removes ambiguity during a stressful, time-pressured event. A plan does not prevent incidents or detect them by itself.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":157,"explanation":178},"019f686c-597b-7aeb-978c-269147da4a79","A typical incident response lifecycle is described as an ordered set of phases. Which sequence best reflects that order?",[170,172,174,176],{"key":154,"text":171},"Recovery, then detection, then containment, then preparation.",{"key":157,"text":173},"Preparation, detection and analysis, containment\u002Feradication\u002Frecovery, then lessons learned.",{"key":160,"text":175},"Eradication, then preparation, then lessons learned, then detection.",{"key":163,"text":177},"Lessons learned first, followed by containment, then preparation, then detection.","The widely taught lifecycle starts with preparation (before anything happens), moves to detection and analysis once something looks wrong, then containment\u002Feradication\u002Frecovery to stop and clean up the incident, and closes with a lessons-learned review that feeds back into preparation.",{"id":180,"topic":9,"difficulty":181,"body":182,"options":183,"correct_key":160,"explanation":192},"019f686c-597c-78e8-8ee6-1ebdd62588b3",2,"A monitoring tool fires an alert every few minutes for a pattern that, after investigation, almost always turns out to be harmless. Why does this matter for incident response?",[184,186,188,190],{"key":154,"text":185},"It has no practical effect, since every alert should be treated with exactly the same urgency regardless of history.",{"key":157,"text":187},"It means the underlying monitoring should be turned off entirely, since alerts that are usually harmless provide no value.",{"key":160,"text":189},"It causes alert fatigue, making responders more likely to dismiss or delay attention to a real incident hidden among the noise.",{"key":163,"text":191},"It automatically qualifies as a security incident on its own, simply because an alert fired repeatedly.","High-noise, low-signal alerts train responders to tune them out (alert fatigue), which is a real triage risk: a genuine incident can be missed or delayed because it looks similar to routine noise. The fix is tuning or triage rules, not blanket ignoring or blanket urgency.",{"id":194,"topic":9,"difficulty":181,"body":195,"options":196,"correct_key":163,"explanation":205},"019f686c-597d-7afb-a26d-b5e4dec93769","A workstation is confirmed to be running malware that is actively communicating with an external address. The workstation is not critical to production. What is the most appropriate immediate containment action?",[197,199,201,203],{"key":154,"text":198},"Leave the workstation fully connected and simply lower its alert priority so it stops generating notifications.",{"key":157,"text":200},"Wait until the next scheduled maintenance window before taking any action on the workstation.",{"key":160,"text":202},"Reformat and reinstall the workstation immediately, before anyone reviews what happened.",{"key":163,"text":204},"Disconnect the workstation from the network (or block its outbound traffic) while preserving its state for review.","Isolating the host — pulling it off the network or blocking its outbound traffic — stops the malware from communicating further while keeping the machine intact for analysis. Lowering priority ignores the incident; waiting for maintenance delays containment; immediate reformatting destroys evidence before root cause is understood.",{"id":207,"topic":9,"difficulty":150,"body":208,"options":209,"correct_key":154,"explanation":218},"019f686c-597e-74a3-abe4-ad249f6b9c2a","In the incident response lifecycle, what does the eradication phase primarily aim to accomplish?",[210,212,214,216],{"key":154,"text":211},"Remove the root cause of the incident (such as malware, a rogue account, or the exploited flaw) so it cannot simply reappear.",{"key":157,"text":213},"Restore the affected systems to normal service without checking whether the underlying cause was addressed.",{"key":160,"text":215},"Write the final report summarizing what happened, several weeks after the systems are already back online.",{"key":163,"text":217},"Notify customers about the incident regardless of whether the technical root cause has been identified.","Eradication follows containment: once the incident is contained, responders remove the actual cause — malicious files, backdoor accounts, the exploited vulnerability — so the same issue does not simply resurface once systems are reconnected.",{"id":220,"topic":9,"difficulty":181,"body":221,"options":222,"correct_key":157,"explanation":231},"019f686c-597f-7098-afa7-6ae2e649883c","After eradicating malware from a compromised server, a team is about to bring it back into production during the recovery phase. What should they do before fully restoring normal traffic?",[223,225,227,229],{"key":154,"text":224},"Immediately route full production traffic back to the server, since eradication already finished.",{"key":157,"text":226},"Bring the server back gradually while actively monitoring for signs the compromise indicators reappear.",{"key":160,"text":228},"Skip monitoring entirely, since the incident is now officially closed once eradication is done.",{"key":163,"text":230},"Restore the server from the most recent backup without checking whether that backup also contains the compromise.","Recovery is not just 'flip it back on' — it typically involves staged restoration with heightened monitoring to confirm the same indicators of compromise do not return, since eradication can occasionally miss something. Restoring from an unverified backup risks reintroducing the same problem.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":181,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]