skip to content

Core Concepts and Threat Actors

You will follow one flaw from the identifier that names it to the working attack it becomes and the adversary who runs it. Interviewers open here because the confident answer is usually wrong.

on this pageshow

explore

questions

page 2 of 2

Your fix policy gives "authenticated only" flaws 90 days and unauthenticated ones 7 — would you defend that split or change it?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

Defensible only if the classes track a position your estate does not hand out. Re-cut the boundary from advisory wording to who already holds the position, add chain and population escalation clauses, and keep a window on every class.

open as a page

A guessable cross-tenant report identifier or a critical parser memory bug — which gets the one remediation slot you can fund this quarter against commodity criminals?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Fund the identifier. It is usable on reading by every account holder, so a crew with no exploit-development budget can use it today, while converting the parser defect needs funded research they would have to buy. Severity ranks impact, not distance.

open as a page

A compliance owner wants all 300 CWE-20 findings closed as one remediation item. What do you argue?

level: principalimportance: nice to knowfreq 22%

basics

~20 s

A Class label is a vocabulary term, not a work item. Three hundred rows sharing it span unrelated resources and unrelated fixes, so closing them together closes nothing. Re-map the dominant ones to Base instead.

open as a page

Your executive reads "nation-state actor" and wants a budget line - what does that label justify funding?

level: principalimportance: nice to knowfreq 36%

basics

~20 s

It justifies funding what patience and return require: access paths that stay closed after eviction, and authentication a stolen secret cannot satisfy. It does not justify buying against exotic capability, because the label asserts sponsorship, not novel exploits.

open as a page

An executive says insider risk is covered because 'we trust our staff'. How do you answer?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Answer without arguing about honesty. Trust addresses at most one of three insider problems and none of the loss from carelessness or a taken session, so move the decision from who holds a role to what that role may reach, and price the smallest scope cut you can defend.

open as a page

Budget funds either shrinking your enumerable internet footprint or hardening supplier paths — which?

level: principalimportance: nice to knowfreq 29%

basics

~20 s

Fund the footprint first: it is the only one of the two that removes an order of targeting rather than redirecting it. Take supplier terms at contract renewal, and name the name-first order as accepted, not covered.

open as a page

showing 31–36 of 36