skip to content

Evidence and Exceptions

A green run is worth only what its record proves, and every ruleset eventually meets a change that legitimately breaks it. Interviewers use evidence and waivers to separate discipline from theatre.

on this pageshow

explore

questions

12

Your 90-day password rotation check passes on every account — what risk does it not cover?

level: juniorimportance: must knowfreq 62%

answer

  1. green measures activity, not the attack
  2. two separate questions, one answer
  3. rotation does not touch phishing
  4. stolen session survives a new password
  5. leaver accounts and rotation are unrelated

basics

~20 s

It proves only that passwords change on schedule. It says nothing about phishing, stolen session tokens, or accounts that were never removed. A green control measures the activity someone wrote down, not the attack it was meant to stop.

solid answer

~40 s

The check measures one activity: that a password value was replaced within 90 days. The risk it was written for is account takeover, and the paths attackers actually use — phishing a password and the one-time code with it, replaying a stolen session token, an account that stayed live after the person left — are all untouched by rotation. Modern authentication guidance (NIST SP 800-63B) actually recommends against forced periodic rotation unless there is evidence of compromise, because it pushes people toward predictable mutations. So the honest reading of the green result is: this control is satisfied, and I still do not know whether account takeover is harder. Those are two separate questions, and a passing check only ever answers the first.

go deeper

for a junior

Be ready to state plainly what the check literally verifies and then list two attack paths it leaves open. Naming phishing and a live session after a password change is enough at this level.

for a middle

Explain why checkable controls drift toward activity metrics, and describe what an outcome-shaped check on the same threat would query instead.

for a senior

Show you can hold the obligation and the gap together: the evidence is legitimate, the threat is not reduced, and here is the replacement control with its own check and its own evidence.

for a principal

Own the reporting risk. When leadership reads a 98 percent pass rate as an assurance statement, the fix is a second reported axis, not a louder caveat in the appendix.

## The two questions a green check answers, and the one it does not Every automated compliance check answers exactly one question: **is the thing the control describes true right now?** People routinely read it as answering a second, much larger question: **is the risk this control exists for actually reduced?** Keeping those apart is the whole skill this topic tests. A 90-day password rotation check reads account metadata and asserts that every password was last set within 90 days. When it is green, the following is true: password values change on a schedule. The following is *not* established: - that an attacker cannot phish a password (and, in the same session, the one-time code that goes with it); - that a stolen session token or refresh token is useless — rotating the password after the theft does not necessarily invalidate a live session, and the attacker was already in; - that accounts belonging to people who left the company are gone; - that a password reused from a breached third-party site is not in circulation. Rotation was invented for a world of offline password databases and long-lived static credentials, where forcing a change bounded how long a leaked hash stayed useful. Current guidance has moved: **NIST SP 800-63B recommends verifiers do not require arbitrary periodic password changes**, and instead force a change only on evidence of compromise, because mandatory rotation reliably produces `Summer2026!` becoming `Autumn2026!`. So the control is not merely incomplete; the activity it mandates can make the underlying risk slightly worse while reporting green every quarter. ## The pattern, not the example Call it **satisfied but ineffective**: the check is correct, the run is green, the evidence is real, and the risk is untouched. It is not a bug. Nothing is broken and there is nothing to fix in any system — the defect is in the control's *definition*. It happens for a structural reason. Controls get written so they can be checked, and checkability selects hard for **activity metrics** — did a thing happen, on time, everywhere — over **outcome metrics**, which are harder to define and often need data the compliance function does not hold. 'Password changed within 90 days' is a query. 'Account takeover is hard' is not. A second control from the same family shows the same shape. 'Quarterly access review completed' is green when every manager clicked through a list of their reports' entitlements and pressed approve. It is genuinely useful when done well. It is also compatible with three leavers keeping access for six weeks, because the review is a snapshot on a 90-day cycle and joiner-mover-leaver failures happen on the day someone changes role. Two green controls, and the actual exposure — nobody has a phishing-resistant factor, and departures are not wired to deprovisioning — sits entirely between them. ## How to answer without sounding cynical Interviewers are not looking for 'compliance is theatre'. They are looking for someone who can hold both facts at once: 1. **The control is satisfied and the evidence is legitimate.** If a framework or a customer contract requires rotation, the green run is a real obligation met, and saying so is not a concession. 2. **The threat it names is not measurably reduced**, and here is what would reduce it: a phishing-resistant second factor on every privileged account, session revocation on password change, deprovisioning triggered by the HR leaver event rather than by a quarterly review, and alerting on impossible-travel or new-device sign-ins. The useful move is to name the threat first and then ask what a check on *it* would look like. For account takeover: what fraction of privileged accounts have a phishing-resistant factor enrolled, and how long does it take from a leaver event to access being revoked? Both are queryable, both have variance, and both go red when the risk gets worse — which is the property the rotation check lacks. ## What this is not Do not confuse it with a **broken** check (the query is wrong, or it passes because it silently matched nothing) or a **misscoped** one (it only ever looked at one directory). Those are defects in the implementation and you fix the check. Satisfied-but-ineffective means the check is a faithful implementation of a control that was aimed at the wrong thing, so the change you are asking for is to the wording of the control itself.

  • If rotation is the wrong control, what would you replace it with?
    Controls aimed at the actual takeover paths: a phishing-resistant second factor enrolled on every privileged account, sessions and refresh tokens invalidated on credential change, deprovisioning triggered by the HR leaver event rather than a quarterly review, and screening new passwords against known-breached lists. Each of those is queryable, so each can be a check with evidence — and each goes red when the exposure actually grows, which the 90-day check never does.
  • Does the green run still have any value?
    Yes, two kinds. It satisfies an obligation, which is real when a framework or a customer contract names rotation, and it proves the account inventory and the evidence pipeline work end to end. What it does not do is support a claim about account security. Reporting it as 'accounts are secure' rather than 'the rotation control is satisfied' is where the harm starts.
  • How would you spot this pattern in a control you have never seen before?
    Read the control and ask what attack it names, then ask what an attacker would do differently if the control were satisfied everywhere. If the answer is 'nothing', it is measuring activity rather than outcome. A second tell is that the metric has no variance — a control that has been 100 percent green for eight quarters is either genuinely solved or is not measuring anything that moves.

A restaurant that proves it washed the floors every night. True, recorded, and no evidence at all about what is happening in the fridge.

saying these in an interview costs you the question

  • Says a passing control means the risk is handled
  • Treats rotation frequency as a measure of account security
  • Argues 30-day rotation would close the gap
  • Calls the check broken when the check is correct
  • Dismisses the whole control as theatre with no replacement

context

open as a page

What must an automated backup-retention check record so its result works as audit evidence later?

level: juniorimportance: must knowfreq 63%

basics

~20 s

Each record needs the verdict plus everything that makes it re-checkable: which control it proves, which resource was evaluated, the exact rule version and input it saw, when it ran, and which identity ran it.

open as a page

What must a policy-as-code waiver record carry besides the rule id and a reason?

level: juniorimportance: must knowfreq 64%

basics

~20 s

A usable waiver names five things: who owns it, exactly what it covers, why the rule cannot be met, who approved it, and when it expires. A rule id plus free text is a note, not a waiver.

open as a page

How do you make a waiver's expiry date enforced by the engine rather than documentation?

level: middleimportance: must knowfreq 52%

basics

~20 s

Store expiry as a timestamp in the exception record and have the rule compare it to the time it is deciding. Past the date the record stops matching, so the original rule denies again with no human action required.

open as a page

How do you make a stored compliance evidence record tamper-evident to an auditor?

level: middleimportance: should knowfreq 42%

basics

~20 s

Hash each record, chain each hash to the previous record's, and sign the chain head with a key the producing job cannot reuse. Store the records in append-only storage locked for the retention period the framework requires.

open as a page

How do you use incident data to show a green compliance control is not reducing risk?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Map each of the last dozen incidents to the controls that were green throughout it. That table turns opinion into measurement, and the argument it supports is a change to the control's wording, brought with a replacement check.

open as a page

An auditor wants last quarter's policy evaluation re-run to reproduce the same verdict — what makes that possible?

level: seniorimportance: should knowfreq 51%

basics

~20 s

Reproduction needs the archived input, the exact rule version, the engine version and any external data the rule used, all pinned by digest. It becomes impossible when the rule evaluated live state instead of a captured input.

open as a page

When every expiring policy waiver is renewed unchanged each quarter, what makes a renewal real?

level: seniorimportance: should knowfreq 46%

basics

~10 s

A real renewal re-answers the original question with fresh evidence and a fresh approval, and usually shortens the expiry. A date bump applied to an unchanged record is silent extension wearing a process.

open as a page

Your security backlog is all audit checkboxes while incidents come from elsewhere — how do you rebalance?

level: principalimportance: should knowfreq 38%

basics

~20 s

Split the work into two funded portfolios: obligations, satisfied and evidenced as cheaply as possible, and risk reduction, funded by measured exposure. Then change what gets reported, because one pass-rate number always pulls the backlog toward checkboxes.

open as a page

Your services all use mTLS but no compliance control covers it — why does that matter?

level: middleimportance: nice to knowfreq 30%

basics

~20 s

A defence nobody checks is invisible to the report leadership funds from. It gets no owner, no budget and no alarm when it regresses, it earns no audit credit, and a redundant product gets bought to solve it again.

open as a page

Your team both operates the backup-retention control and produces its evidence — why should an auditor trust that?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

You cannot assert trustworthiness; you engineer it. Split the paths so the team that operates the control cannot silently alter, delete or forge its evidence, and let someone outside the team verify a sample independently.

open as a page

Who may approve a policy waiver on a rule that their own team owns?

level: principalimportance: nice to knowfreq 33%

basics

~10 s

Not the person asking for it. Approval should sit with someone accountable for the risk rather than the deadline, and authority should scale with how wide and how long the exception is.

open as a page