- Threat-model a multi-tenant export/reporting feature.
- Review password reset and account recovery for takeover and privacy risk.
- Design a secure webhook platform.
- A team has 5,000 dependency alerts. How do you prioritize and reduce recurrence?
- Place SAST, SCA, DAST, secret, IaC, container, and runtime controls in the lifecycle.
- Design an exception process engineers will use without making it a bypass.
- What metrics show that a product security program is reducing risk?
- Explain a critical design flaw to a product VP and provide options.
- Design a landing zone for a regulated multi-account organization.
- Trace a federated human login and workload identity to a cloud data object.
- Prevent and detect cross-tenant access in a Kubernetes SaaS platform.
- Respond to a leaked CI credential with broad cloud permissions.
- Secure Terraform state, plan review, deployment identity, and module supply chain.
- Compare namespace, cluster, gVisor, and microVM tenant boundaries.
- Design centralized logging that survives a compromised workload or project.
- Map a compliance requirement to implementation, test, owner, evidence, and frequency.
- Design backup and recovery for ransomware-like data corruption without teaching ransomware.
- Prioritize cloud findings for an executive remediation roadmap.
- Explain app sandbox, permission, Binder caller identity, and SELinux boundaries.
- Review a deep link that initiates a payment or sensitive workflow.
- Secure a content provider shared with one partner application.
- Threat-model a WebView JavaScript bridge.
- Choose storage for offline sensitive records.
- Assess certificate pinning and design rotation/failure behavior.
- Triage a crash in a JNI image parser.
- Explain APK signing, Verified Boot, Keystore, and hardware attestation as separate controls.
- An app passes mobile tests but its API has broken object authorization. How do you report it?
- Plan a responsible Android research project using AOSP or an owned app.
- Design a service that runs untrusted customer code.
- What remains shared in containers, gVisor-style sandboxes, and microVMs?
- Derive a seccomp profile and handle compatibility.
- Contain a fork bomb, memory consumer, filesystem probe, and metadata request.
- Compare Linux capabilities/LSMs, Windows tokens/integrity, and macOS sandbox/TCC.
- Design endpoint logging with privacy and cost constraints.