Core Concepts and Threat Actors
You will follow one flaw from the identifier that names it to the working attack it becomes and the adversary who runs it. Interviewers open here because the confident answer is usually wrong.
on this pageshowhide
explore
- Naming a Flaw8 questions
- What a CVE Claims4 questions
- CWE Abstraction Levels4 questions
- From Flaw to Weapon16 questions
- The Weaponisation Ladder4 questions
- Flaws Needing No Exploit4 questions
- The Zero-Day Window4 questions
- Position, Not Barrier4 questions
- Who Runs the Attack12 questions
- Actor Classes as Predictions4 questions
- The Insider Model4 questions
- The Order of Targeting4 questions
questions
page 2 of 2Your fix policy gives "authenticated only" flaws 90 days and unauthenticated ones 7 — would you defend that split or change it?
basics
~20 sDefensible only if the classes track a position your estate does not hand out. Re-cut the boundary from advisory wording to who already holds the position, add chain and population escalation clauses, and keep a window on every class.
A guessable cross-tenant report identifier or a critical parser memory bug — which gets the one remediation slot you can fund this quarter against commodity criminals?
basics
~20 sFund the identifier. It is usable on reading by every account holder, so a crew with no exploit-development budget can use it today, while converting the parser defect needs funded research they would have to buy. Severity ranks impact, not distance.
A compliance owner wants all 300 CWE-20 findings closed as one remediation item. What do you argue?
basics
~20 sA Class label is a vocabulary term, not a work item. Three hundred rows sharing it span unrelated resources and unrelated fixes, so closing them together closes nothing. Re-map the dominant ones to Base instead.
Your executive reads "nation-state actor" and wants a budget line - what does that label justify funding?
basics
~20 sIt justifies funding what patience and return require: access paths that stay closed after eviction, and authentication a stolen secret cannot satisfy. It does not justify buying against exotic capability, because the label asserts sponsorship, not novel exploits.
An executive says insider risk is covered because 'we trust our staff'. How do you answer?
basics
~20 sAnswer without arguing about honesty. Trust addresses at most one of three insider problems and none of the loss from carelessness or a taken session, so move the decision from who holds a role to what that role may reach, and price the smallest scope cut you can defend.
Budget funds either shrinking your enumerable internet footprint or hardening supplier paths — which?
basics
~20 sFund the footprint first: it is the only one of the two that removes an order of targeting rather than redirecting it. Take supplier terms at contract renewal, and name the name-first order as accepted, not covered.
showing 31–36 of 36