{
 "schemaVersion": 1,
 "pathSlug": "soc2-operator",
 "items": [
  {
   "questionId": "compliance.soc2_basics__200103",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the correct characterization of a SOC 2 Type 1 report?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An auditor opinion on whether controls are suitably designed as of a single point in time"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "An auditor opinion on whether controls operated effectively over a defined review period of months"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A continuous monitoring artifact streamed from compliance automation platforms to customers"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A management self-assessment of control design completed before any audit fieldwork begins"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__17201",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Access review control is documented annually but never executed. Which gap is present?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An operating-effectiveness gap: the control is suitably designed on paper but did not operate at its stated cadence during the period"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A scoping gap: an unperformed access review should be carved out of the system description entirely"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A design gap: the documented control would fail to meet CC6 even if it had been performed on schedule"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A documentation gap: the policy text needs rewording before the auditor will accept the missing reviews"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__50998",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An engineering team is choosing between Drata, Vanta, and Secureframe for SOC 2 readiness. What dimension matters most in the selection?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Whether the platform shares an investor with the CPA firm engaged to issue the final SOC 2 opinion"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Whether the platform brands itself as enterprise-grade in its marketing material and customer reference list"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Whether the platform offers the highest count of pre-built policy templates regardless of integration depth"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Whether the platform's integration catalog covers the entity's actual stack (cloud, IdP, code host, HRIS, ticketing) for automated evidence"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__17148",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Two SaaS teams have similar policies. Team A maintains an owner-mapped control matrix; Team B does not. Which audit-cycle outcome does Team A typically achieve?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A faster path to an unqualified opinion, because owner-mapped controls are reviewed less rigorously than orphaned ones"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Repeatable evidence collection across periods, because each control names an accountable owner and a deterministic evidence source"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Exemption from sampling, because owner attestation removes the auditor's need to test per-instance evidence in the window"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A reduced count of Common Criteria in scope, because mapped controls collapse adjacent CC families during fieldwork"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__100001",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A startup is choosing between a SOC 2 Type 1 and a SOC 2 Type 2 report for its first audit. What is the core distinction between the two report types?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Type 1 covers only the Security criterion at a point in time; Type 2 adds Confidentiality and Privacy across the same single date assessment"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Type 1 attests to control design at a single point in time; Type 2 attests to operating effectiveness over a period (typically 6-12 months)"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Type 1 is issued by the company itself; Type 2 requires a CPA firm to attest to the same controls without any extended period of review"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Type 1 requires Drata or Vanta automation evidence; Type 2 permits manual evidence collection across the full audit window without tooling"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__31199",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How does vendor management relate to SOC 2 compliance, and what due diligence is required for third-party service providers?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Vendor management in SOC 2 only applies to direct competitors; business partners are considered trusted by default"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Vendors are entirely responsible for their own SOC 2 compliance; the customer organization has no related obligations"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 requires assessing third-party vendors' security controls, reviewing their SOC 2 reports, maintaining contracts with security requirements, and monitoring vendor access"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 prohibits using cloud services like AWS or GCP since they introduce uncontrolled third-party risks"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__51003",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How does the DSA's transparency reporting requirement (effective July 2025) create new SOC 2 considerations for platforms?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 auditors are prohibited from reviewing DSA-related controls"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "DSA transparency reports can substitute for SOC 2 Type 2 audit reports"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The DSA eliminated all SOC 2 requirements for European platforms"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Platforms must implement auditable processes for content moderation reporting, which can provide evidence for multiple SOC 2 Trust Services Criteria including security and processing integrity"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__400021",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How does the AICPA's SOC 2 framework differ from the AICPA's SOC for Cybersecurity (SOC-C) in target audience and scope?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 attests to a service organization's controls for use by its customers; SOC for Cybersecurity reports on an entity's enterprise-wide cybersecurity risk program for broader stakeholders"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 is delivered orally to internal stakeholders only; SOC for Cybersecurity is the written equivalent for the same internal audience under the same AICPA reporting standard"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 is a checklist self-assessment without auditor involvement; SOC for Cybersecurity is the auditor-validated form of that same checklist for the same service-organization audience"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 is reserved for organizations under 500 employees; SOC for Cybersecurity is reserved for any organization above that headcount threshold operating any cyber program"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__300010",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A team has shipped controls and is choosing whether the first SOC 2 observation period should be three months versus a full twelve months. What is the trade-off between a shorter and a longer initial Type 2 period?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A shorter period yields a report sooner but with less operating evidence; a longer period builds stronger evidence but delays the first customer-shareable report"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A shorter period reduces the number of Trust Service Criteria the auditor must test; a longer period forces inclusion of every elective criterion regardless of customer demand"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A shorter period legally caps the auditor's opinion to a qualified one; a longer period guarantees an unqualified opinion regardless of how controls performed during testing"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A shorter period removes the requirement for a written management assertion; a longer period requires the assertion plus a separately signed CEO attestation document"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__915327",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An eng team runs "
      },
      {
       "t": "code",
       "v": "terraform destroy"
      },
      {
       "t": "text",
       "v": " on dev infra mid-audit, wiping CloudTrail history for an in-scope test account. The auditor flags it as a control failure under CC7. What's the underlying gap?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Logging infrastructure for in-scope systems must rotate retention windows monthly to satisfy AICPA log freshness rules"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Logging infrastructure for in-scope systems must be reviewed line-by-line by the engineering manager every audit week"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Logging infrastructure for in-scope systems must be hosted entirely on dedicated bare-metal outside the cloud tenant"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Logging infrastructure for in-scope systems must be protected from modification or destruction by the same users it monitors"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__403672",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Tabletop exercise: the scenario has ransomware encrypting the audit log store and the backup S3 bucket. The IR lead announces 'we restore from backup'. The compliance engineer pushes back on this single-line plan. What auditor-visible weakness are they pointing to?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Restoring overwrites forensic evidence and the chain-of-custody record needed for the breach assessment"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Restoring from backup is forbidden until law enforcement formally takes custody of the encrypted volumes"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Restoring from backup invalidates the SOC 2 control over backup integrity testing for the audit period"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Restoring from backup requires a separate disaster-recovery declaration before any restore command runs"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__17121",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "At 02:00 in an active breach, the engineering lead and the head of communications disagree about whether to email customers in the next hour. The runbook is silent on this. Which runbook element was missing?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The template language for customer-facing apology emails and the legal-team turnaround time on copy reviews"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The named decision-owner authorised to approve external comms and the trigger conditions for doing so"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The escalation contact for the cloud-provider account team and their preferred channel for ticket priority bumps"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The list of approved comms tooling vendors and the procurement steps to onboard a new vendor during outages"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__1379452",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A post-incident control-update tracker emits a SOC 2 evidence row. Given the incident dict, what is printed?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "def soc2_row(inc):\n    status = \"closed\" if inc[\"postmortem\"] else \"open\"\n    tag = \"cc7.5_satisfied\" if inc[\"control_updates\"] > 0 else \"cc7.5_unsatisfied\"\n    return (inc[\"id\"], status, inc[\"control_updates\"], tag)\n\nprint(f\"row={soc2_row({'id':'INC-42','postmortem':True,'control_updates':3})}\")",
    "label": "incident-response.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "row=('INC-42', 'closed', 0, 'cc7.5_unsatisfied')"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "row=('INC-42', 'open', 3, 'cc7.4_satisfied')"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "row=('INC-42', 'closed', 3, 'cc7.4_acknowledged')"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "row=('INC-42', 'closed', 3, 'cc7.5_satisfied')"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__51016",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What enforcement power does the European AI Office have for investigating incidents involving GPAI models?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "No enforcement power until member states complete their own investigations"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The ability to request documentation, conduct evaluations, demand source code access, and impose corrective measures"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Authority limited to requesting a written explanation within 90 days"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Only the power to issue non-binding recommendations to model providers"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__104736",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "HHS issued guidance in late 2024 reiterating HIPAA Breach Notification Rule timelines for breaches affecting 500+ individuals. By when must a covered entity notify HHS of such a breach?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Without unreasonable delay and in no case later than annually as part of the HIPAA wrap-up report"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Without unreasonable delay and in no case later than 30 calendar days after discovery of the breach"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Without unreasonable delay and in no case later than 60 calendar days after discovery of the breach"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Without unreasonable delay and in no case later than 72 hours after discovery of the breach event"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__1284037",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An IR escalation engine resolves the strictest external deadline for a breach impacting EU residents, US patients, and cardholder data. What is printed (hours)?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "deadlines = {\n    \"gdpr_authority\": 72,\n    \"hipaa_hhs_500plus\": 60 * 24,\n}\nstrictest = min(deadlines.values())\nprint(f\"strictest_external_deadline_hours={strictest}\")",
    "label": "incident-response.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "strictest_external_deadline_hours=72"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "strictest_external_deadline_hours=24"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "strictest_external_deadline_hours=60"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "strictest_external_deadline_hours=96"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__17120",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A security lead is choosing between an annual tabletop and an annual live drill to satisfy the 'plan tested' control. What is the differential value a tabletop delivers that a live drill does not?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Demonstrates that monitoring alerts fire correctly during a real chain of triggered detections and pages"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Validates that runbook commands execute correctly against the current state of production infrastructure"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Surfaces decision-authority and communication gaps cheaply because no production systems are touched"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Produces measurable mean-time-to-contain numbers that can be compared against prior live drill results"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__31203",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "During an active breach the team has isolated the compromised host and confirmed the malware family, but the same indicators reappear on a second host four hours later. Which NIST SP 800-61r2 phase did the team likely under-execute before declaring containment complete?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Detection and analysis, because the SIEM correlation rules failed to fire on the secondary host until manual review"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Eradication of the underlying cause across the affected environment, not only on the host where the indicator first surfaced"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Post-incident activity, because the lessons-learned meeting had not yet been scheduled by the incident commander"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Preparation, because the runbook for this malware family had not been reviewed since its last quarterly update cycle"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__200101",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "On detecting a confirmed breach affecting EU personal data, an on-call engineer immediately terminates the compromised EC2 instance to stop further data exfiltration, then opens a ticket to begin investigation. The consultant brought in the next morning reports there is nothing left to analyze. What did the engineer get wrong relative to a typical IR playbook?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The on-call should have filed a customer-facing notification before containment so affected parties learn of the breach from the company instead of media"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The on-call should have rotated the IAM credentials attached to the workload before any containment action so attacker persistence is severed first"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Termination destroyed volatile memory and ephemeral disk state before a snapshot or memory capture was taken to preserve evidence for the forensics step"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The on-call should have notified the supervisory authority before any containment action because GDPR requires regulator engagement to precede technical response"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__915627",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A test harness runs the IR plan tabletop frequency check. What is printed?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "MIN_IR_TABLETOP = \"annually\"\n\ndef plan_status(plan):\n    if not plan[\"documented\"]:\n        return \"plan_missing\"\n    return f\"tabletop_due={MIN_IR_TABLETOP}\"\n\nprint(plan_status({\"documented\": True}))",
    "label": "incident-response.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "tabletop_due=quarterly"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "tabletop_due=annually"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "tabletop_due=monthly"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "tabletop_due=biennial"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__200152",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the correct characterization of structured audit log fields?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Each event is enriched at read-time by a sidecar that infers fields from the message text body"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Each event is rendered as a human-readable prose sentence written by the application developer"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Each event has typed, named attributes so logs can be queried and filtered without text parsing"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Each event is serialized into a compact binary frame designed to minimize on-disk storage cost"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__17177",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An auditor reviews policy-edit entries and finds that each one records only that an edit happened, not what changed. Which forensic capability is most directly undermined?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Correlating the policy edit with related events across services"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Reconstructing the before-and-after state of the modified policy"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Identifying which downstream service first observed the edit"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Classifying the severity of each policy-edit event at ingestion time"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__471038",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "PCI DSS v4.0 became the only valid version for assessments in 2024. Which audit-logging requirement did v4.0 newly mandate beyond what v3.2.1 required?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Quarterly external vulnerability scanning of all logging infrastructure by an approved vendor"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Manual daily log review by a designated team member with sign-off in a ticketing system"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Automated log review mechanisms for daily review of security events across in-scope systems"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Annual penetration testing focused specifically on the centralised log aggregation pipeline"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__31162",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your team is designing the schema for an audit event covering a GDPR-relevant access to personal records. Which field set best balances accountability with the minimisation principle?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Only the principal and the resource field name; the actual values returned by the access must never appear"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Only delete operations are logged in audit; read and update activity stays in the application's operational logs"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A complete before-and-after snapshot of every record that the operation read, modified, or deleted at runtime"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Principal, UTC timestamp, action, resource identifier, data classification, purpose, and request context (IP, session)"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__17107",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "When designing an audit log for a system that handles regulated data, which event class returns the highest forensic value per byte stored?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Privileged access and permission changes"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Cache hit and miss counters from the edge layer"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Heartbeat pings from internal monitoring agents"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Every successful read of a public marketing page asset"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__200153",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the role of an immutable storage tier (e.g. S3 Object Lock) in audit logging?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It encrypts every uploaded object with a customer-managed key rotated monthly by the storage provider"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It compresses uploaded objects in place to keep retention budgets within the SOC reporting period"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It enforces retention by blocking overwrite and deletion of objects within the configured window"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It indexes uploaded objects by content hash so auditors can perform similarity searches at scale"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__17176",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An auditor notes that the production app role can edit and delete entries in the security event store. Which audit property has been violated?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Centralisation of the entries from multiple emitting services"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Confidentiality of the entries against unauthorised readers"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Integrity and tamper resistance of the stored entries"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Retention of the entries for the required regulatory window"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__17134",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your team wants the central audit store to give an auditor a defensible answer when asked 'could a privileged operator have rewritten a prior entry?'. Which design most directly supplies that answer?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Append-only storage with cryptographic integrity verification"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Weekly compression of older segments without integrity manifests"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Periodic copy of entries into long-form email summaries"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Disk-full triggered rotation that overwrites the oldest entries"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__1361784",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your SaaS supports US public-company customers in 2025. Their internal audit team cites SOX retention expectations for audit logs of financial-system-adjacent activity. Which retention horizon now anchors the contractual ask?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Five years of retention for events touching systems in scope for financial reporting controls"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Three years of retention for events touching systems in scope for financial reporting controls"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Seven years of retention for events touching systems in scope for financial reporting controls"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Ten years of retention for events touching systems in scope for financial reporting controls"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__200344",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A dev logs audit events as a single 'message' string like 'user u_123 changed role of u_456 from member to admin'. The auditor asks for a list of all role escalations to admin in the last quarter and the dev spends a day writing regex. What was the gotcha the dev missed up front?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Audit events should be emitted as plain text but indexed by a search engine like OpenSearch so regex queries run efficiently against the message body"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Audit events should be emitted as plain text but the actor and target ids must always appear in the same column position for log-shipper parsing"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Audit events should be emitted as structured fields (actor, action, target, before, after) so they can be queried without parsing free-text messages"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Audit events should be emitted as plain text but each message must begin with a fixed prefix tag so downstream consumers can filter by event class"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__400005",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best characterises 'sensitive authentication data' (SAD) versus cardholder data (CHD) under PCI-DSS?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SAD is the truncated representation kept for fraud analytics and is retained per the merchant's analytics policy."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "SAD (full track, CAV2/CVC2/CVV2/CID, PIN/PIN block) must not be retained after authorisation, even when encrypted."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SAD comprises the printed name, billing postcode, and expiry, and may be retained alongside the PAN if encrypted."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SAD is the tokenised surrogate produced by the vault and is freely retained because it is not the original value."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__100002",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best characterises a 'public' tier in a four-tier sensitivity scheme?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Disclosure causes no foreseeable harm; the data is approved for unrestricted external publication."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Disclosure outside the company would create competitive harm and requires legal review before any release."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Disclosure is restricted to staff and contractors who have signed the standard confidentiality undertaking."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Disclosure to anyone outside the originating team requires a documented business need and an access ticket."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__50934",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What new data category must automated classification systems now account for under 2025-2026 AI governance requirements?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "DNS query logs, classified as critical infrastructure telemetry"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Social media engagement metrics, classified as behavioral biometrics"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "AI training data sets, requiring distinct classification and lineage tracking"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Blockchain transaction hashes, classified as public financial records"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__871935",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A DSAR collector groups one subject's records by source tier. What does the script print?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "from collections import Counter\nRECORDS=[('kyc','restricted'),('billing','confidential'),\n         ('support','internal'),('crm','restricted')]\n\nc=Counter()\nfor _,tier in RECORDS:\n    c[tier]+=1\nprint(dict(c))",
    "label": "data-classification.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "{'restricted': 3, 'confidential': 1, 'internal': 0}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "{'restricted': 1, 'confidential': 2, 'internal': 1}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "{'restricted': 2, 'confidential': 1, 'internal': 1}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "{'internal': 1, 'confidential': 1, 'restricted': 2}"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__31152",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How should database schemas reflect data classification requirements for a multi-tier application?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Separate physical databases must be used for each classification level, regardless of operational cost"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Store classified data in separate tables or columns with appropriate encryption, auditing, and access controls matching the classification level"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Data classification is purely a documentation concern; database schemas need no special design for classified fields"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "All data should be stored in a single encrypted database regardless of classification: encryption equalizes sensitivity"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__105519",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing token-vault tokenisation versus format-preserving encryption (FPE) for protecting PAN while keeping downstream systems numeric, which point best supports tokenisation for PCI scope reduction?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Vault tokens are always longer than the original PAN by exactly four digits so they cannot fit existing schemas"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Vault tokens require analysts to memorise the original PAN before issuing the token to keep audit trail intact"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Vault tokens are forbidden by PCI DSS v4.0 in any system that processes recurring billing or refunds at scale"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Vault tokens have no mathematical link to the PAN; FPE keeps reversibility inside any system holding the key"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__926108",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A jq filter extracts S3 object tags from a Macie finding. What does the command print to stdout?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "echo '{\"resourcesAffected\":{\"s3Object\":{\"tags\":[\n  {\"key\":\"Classification\",\"value\":\"restricted\"},\n  {\"key\":\"Owner\",\"value\":\"fraud-team\"}]}}}' \\\n| jq -c '[.resourcesAffected.s3Object.tags[] | \"\\(.key)=\\(.value)\"]'",
    "label": "data-classification.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "[\"Classification=restricted\",\"Owner=fraud-team\"]"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "[{\"Key\":\"Classification\",\"Value\":\"restricted\"}]"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "{\"Classification\":\"restricted\",\"Owner\":\"fraud-team\"}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Classification=restricted\\nOwner=fraud-team"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__17130",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A classification programme has been stable for two years. Which kind of event should auto-trigger a reclassification review on a specific dataset?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A team move that places the dataset's owner under a different reporting line in the engineering organisation chart"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A change to the storage cluster's underlying hardware refresh schedule by the platform team's operations group"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A new downstream use, a new sharing partner, or a regulator update changes the dataset's risk profile"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A renaming of the table column that holds the timestamp field used by the operational dashboard for time-series filtering"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__300007",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes how a DSAR (data subject access request) interacts with a classification scheme?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Tier labels exempt regulated stores from the response since regulator-mandated retention overrides the request."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Tier labels delay the response window by adding a documented legal-review step ahead of any data extraction."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Tier labels reduce the response surface to the marketing CRM only, since other tiers are out of scope for DSARs."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Tier labels guide the search across stores so personal-data sources are enumerated within the response window."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__328419",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A lineage walker propagates the maximum upstream tier to each downstream node. What does the script print for node 'report'?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "RANK={'public':0,'internal':1,'confidential':2,'restricted':3}\nINV={v:k for k,v in RANK.items()}\nNODES={'users':'restricted','orders':'confidential','catalog':'internal'}\nEDGES={'report':['users','orders'],'export':['report','catalog']}\n\ndef tier(n):\n    if n in NODES: return RANK[NODES[n]]\n    return max(tier(p) for p in EDGES[n])\nprint(INV[tier('report')])",
    "label": "data-classification.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "regulated"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "restricted"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "confidential"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "internal"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__8228451",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An SPA stores an opaque refresh_token in localStorage. After an XSS in a third-party widget, you see refresh_token rows in your DB being used from attacker IPs minutes after issuance. What is the primary architectural mistake?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Refresh tokens stored without binding the user_agent string into the token payload"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Refresh tokens issued without a per-request CSRF token bound to the cookie origin"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Refresh tokens issued without a corresponding nonce claim in the access token payload"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Refresh tokens stored in JavaScript-accessible storage instead of a HttpOnly cookie"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63725",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does "
      },
      {
       "t": "code",
       "v": "SameSite=None"
      },
      {
       "t": "text",
       "v": " require on a cookie and when is it typically used?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "Set-Cookie: token=xyz; SameSite=None; Secure; HttpOnly",
    "label": "session-management.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It requires Path=/ and is used for API authentication cookies"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It requires Domain to be set and is used for subdomain sharing"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It requires the Secure flag and is used for cross-site contexts"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It requires HttpOnly and is used for session cookies on the same origin"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63717",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which cookie attribute prevents JavaScript from reading the session cookie via "
      },
      {
       "t": "code",
       "v": "document.cookie"
      },
      {
       "t": "text",
       "v": "?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SameSite"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Domain"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Secure"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "HttpOnly"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63919",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the difference between idle timeout, absolute timeout, and sliding window timeout for sessions?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Idle = applies to cookies; Absolute = applies to JWTs; Sliding = applies to API keys"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Idle = server-side only; Absolute = client-side only; Sliding = both combined"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Idle = resets on each request; Absolute = expires after inactivity; Sliding = fixed expiry"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Idle = inactivity; Absolute = fixed time regardless of use; Sliding = resets per request"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__20485",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the difference between session invalidation on logout and session expiry?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Logout removes the session server-side; expiry invalidates it once its window ends"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Logout only clears the client-side cookie without touching the server record"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "They are identical: both merely prevent the session token from being reused"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Session expiry permanently deletes the user account; logout only clears the cookie"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63921",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is an atomic version/index on refresh tokens designed to prevent?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Concurrent rotations issuing extra pairs"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Token payload size exceeding cookie limits"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Key rotation failures during JWKS updates"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "DNS rebinding attacks on the token endpoint"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63718",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the main advantage of server-side (stateful) sessions over stateless JWT sessions?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Stateful sessions keep cookies smaller than an equivalent JWT"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Stateful sessions avoid the need for any network calls between services"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Stateful sessions work across multiple microservices without shared state"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Stateful sessions can be revoked instantly by deleting the session record"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63645",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which cookie attribute ensures the browser only sends the cookie over HTTPS connections?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "HttpOnly"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Secure"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SameSite"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Path"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__19272",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A session cookie is sent on cross-site POST requests and CSRF incidents appear. Which cookie control helps most?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Set Secure so the cookie is only transmitted over HTTPS in cross-site contexts"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Set a long Max-Age so a single cookie covers many cross-site interactions safely"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Set HttpOnly so cross-site scripts cannot read the cookie before the POST is issued"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Set SameSite=Lax or Strict so the cookie is withheld on cross-site POST requests"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63759",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A cookie is set with both "
      },
      {
       "t": "code",
       "v": "Max-Age=3600"
      },
      {
       "t": "text",
       "v": " and "
      },
      {
       "t": "code",
       "v": "Expires"
      },
      {
       "t": "text",
       "v": " pointing to yesterday. What does the browser do?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The cookie lives for 3600 seconds because Max-Age takes precedence over Expires"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The cookie never expires because the conflict disables both of these attributes"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The browser rejects the cookie outright due to conflicting directives"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The cookie is deleted immediately because Expires takes precedence"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__607831",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing 'PEP / PDP / PIP / PAP' separation (XACML) with a monolithic in-process authorize() function, which property is gained by the four-component split?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Decision logic, attribute fetching, enforcement, and administration become components that scale and audit separately"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Authentication is collapsed into authorization because the PIP becomes the only identity provider for the entire deployment"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Decision latency is reduced to zero because the four components share the same call stack and process address space directly"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "OAuth refresh token rotation is automated because the PAP component issues new tokens to clients during decision retrieval"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__500063",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How do reverse-expand operations support list endpoints in ReBAC systems?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Given a subject and permission, the engine enumerates the resources for which that subject is authorized."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Given a resource and action, the engine streams every audit event that touched the resource last quarter."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Given a tenant id, the engine recomputes the role lattice from scratch and broadcasts updates to listeners."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Given a subject id, the engine refreshes the JWT scope claim with the latest organization-wide role bundle."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63930",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A platform adds a brand-new 'archive' resource type. No policy yet mentions it. Under a deny-by-default access-control model, what is the system's response when any user, including the platform owner, tries to read an archive?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "All reads succeed for the owner because new resource types inherit the policy of the closest parent by namespace match"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Only the platform owner can read because owner identity bypasses any deny-by-default check at the gateway during the migration window"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "All reads are denied, with no exception for any requester, until a policy explicitly grants read on the archive type"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The first user to access the resource becomes its de facto owner and inherits the full read-write permission set automatically"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__50360",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Cedar is an authorization policy language originally released by AWS. How is Cedar distributed, and which policy models does its grammar express?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An AWS-only proprietary DSL embedded in IAM that other clouds cannot evaluate"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "An open-source language for fine-grained RBAC, ABAC, and ReBAC policies in one grammar"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A JSON-Schema policy language used by Kubernetes to define cluster-wide RBAC role bindings"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A query language for access-control-list lookups stored as rows in a relational database"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63689",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why should authorization checks verify permissions rather than role names?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "// Prefer:\nif (user.can('documents:edit')) { ... }\n\n// Avoid:\nif (user.role === 'editor') { ... }",
    "label": "rbac.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Permissions are stored in cookies while roles are stored in databases"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Permission names are shorter and faster to evaluate than role names"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "JSON Web Tokens cannot carry role claims, only permission claims"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Role definitions change over time, but permission checks stay stable"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__20523",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An application needs to let users delegate some of their permissions to other users temporarily. Why does standard RBAC struggle with this requirement?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "RBAC binds permissions to roles, so temporary delegation demands a throwaway role"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Delegation requires encrypting permissions, which RBAC does not support natively"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "RBAC cannot be extended to support more than one assigned role per individual user"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "RBAC is session-based and cannot persist delegated permissions across separate logins"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63835",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An app's API validates permissions on the frontend before rendering UI elements, but the backend API endpoints have no authorization checks. What is the vulnerability?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Any client can call the unprotected endpoints directly, bypassing frontend checks"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "CORS blocks unauthorized clients from calling the API from any origin"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The frontend checks are sufficient because users cannot modify the JavaScript bundle"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The backend automatically inherits frontend authorization decisions"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63690",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A team is about to ship a new permission named 'reports:export'. They forget to add it to any role before the release. With the standard deny-by-default RBAC posture, what happens when any user clicks Export?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Only platform-super-admins can export, because the admin path bypasses unmatched permission checks via a hardcoded fast-path"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Every export attempt is denied, because no role grants the new permission, so no subject can satisfy the policy"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Every export attempt errors with HTTP 500, because the engine refuses to evaluate a policy referencing an unmapped permission name"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Every export attempt succeeds, because the engine treats unknown permissions as legacy-compatible and falls through to allow"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63837",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Authorization middleware is written as "
      },
      {
       "t": "code",
       "v": "if (user.role === 'admin') return true; else evaluatePolicy(...)"
      },
      {
       "t": "text",
       "v": ". A new "
      },
      {
       "t": "code",
       "v": "delete:organization"
      },
      {
       "t": "text",
       "v": " permission is added to the policy. What governance problem does the shortcut introduce?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The policy engine cannot add new permissions to the admin role because the shortcut intercepts before role resolution"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Other roles lose access to the new permission because the shortcut consumes the request before the policy engine runs at all"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Admins gain the destructive permission automatically the moment it is defined, with no explicit role-permission grant and no review"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The middleware blocks admins from being demoted because the hardcoded check makes their role assignment immutable in the user directory"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__500064",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What has to happen before a policy-as-code rollout can turn on least-privilege defaults?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Existing TLS certificates must be reissued with stricter chains before any default-deny rollout can begin safely."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Existing implicit grants must be enumerated before a default-deny posture can be safely enabled at the gateway."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Existing identity providers must all be migrated to passkeys before any default-deny posture can be enabled safely."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Existing user passwords must be rotated globally before any default-deny posture can be enabled safely."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__63940",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What key concepts must a Service Provider configure to integrate with a SAML 2.0 Identity Provider?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "OAuth client_id, client_secret, and redirect URI"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Entity ID, ACS URL, and the IdP's X.509 signing certificate"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "JWKS endpoint URL, the issuer claim, and the audience claim"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "API key, webhook callback URL, and rate limit tier"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__63594",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does SSO (Single Sign-On) allow a user to do?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Share their session cookies across different browsers"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Skip multi-factor authentication on all services"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Log in once and reach many apps without re-authenticating"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Use one password for every personal online account they own"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__200011",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What sequence of steps makes up an SP-initiated SSO flow in SAML 2.0?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The application generates a one-time password, emails it to the user, and the user pastes it into the identity provider's web form to start an authenticated browser session"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The user hits the application first, the application redirects to the identity provider with an AuthnRequest, and the provider returns a signed assertion"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The user signs in at a portal first, the portal pushes user attributes to a queue, and applications poll the queue periodically to harvest pending sessions for the user"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The directory service brokers a TLS mutual handshake between the browser and the application after exchanging certificate fingerprints with each tenant of the identity provider"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__20545",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A SAML service provider must prevent replay attacks where an attacker intercepts and reuses a valid SAML assertion. What mechanism does this?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Verify the SAML assertion's NotBefore and NotOnOrAfter timestamps only for freshness"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Require the IdP to use a fresh signing key for each assertion to prevent reuse attacks"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Validate the ACS URL in the assertion matches the SP's registered endpoint configuration"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Track assertion IDs in a short-lived cache and reject any that were seen before"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__200342",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A dev wires an OIDC client to skip the "
      },
      {
       "t": "code",
       "v": "nonce"
      },
      {
       "t": "text",
       "v": " parameter on the auth request because the library 'just works' without it. Pen test flags it. What attack does the missing nonce specifically enable that PKCE alone does not block?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "ID token replay where an attacker injects a previously captured id_token into a victim's session"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Refresh token theft where a stolen refresh token is replayed against the IdP token endpoint"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Cross-site request forgery against the authorization endpoint via a forged state parameter"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Authorization code interception where an attacker injects an intercepted code into the redirect_uri"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__100021",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How does SAML 2.0 convey a user's identity in enterprise federation?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A binary RPC protocol where the application sends raw username and password to the identity provider for verification"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A REST profile where the user posts plaintext claims to the application and the directory validates them out of band"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A JSON-based protocol where the service provider issues a signed bearer token the identity provider validates on each call"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "An XML-based standard where the identity provider issues a signed assertion that the service provider validates"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__405674",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing IdP-initiated SAML with SP-initiated SAML for security posture, which concern is real for IdP-initiated?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Unsolicited assertions bypass the IdP signature check entirely on the assertion-consumer side"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Unsolicited assertions are encrypted but never signed, leaving them vulnerable to replay"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Unsolicited assertions cannot be signed by the IdP, so the SP must trust the user agent"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Unsolicited assertions lack a matching in-flight RelayState, weakening CSRF-style protections"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__63943",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which enterprise SSO best practice protects against IdP compromise or session anomalies?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Disabling session timeouts so users are never signed out"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Storing session IDs in URL query parameters for audit logging"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Allowing users to share SSO credentials with teammates for convenience"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Monitoring SSO sessions for anomalies such as impossible travel"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__63706",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why should an enterprise maintain break-glass accounts alongside SSO?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "They allow users to bypass MFA requirements during emergencies"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "They provide faster login speeds than SSO for privileged users"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "To keep access during an IdP outage or misconfiguration"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Break-glass accounts are required by SAML 2.0 specification"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__50407",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "When is OIDC the preferred SSO protocol over SAML in current enterprise guidance?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "For modern API-first, mobile, and cloud-native applications using JSON tokens"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "For browser-only B2B tools where the SP cannot run JavaScript on the client side"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "For legacy on-premises Windows apps that integrate via Active Directory natively"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "For government workloads where signed XML assertion formats are mandated by policy"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__400774",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does the "
      },
      {
       "t": "code",
       "v": "amr"
      },
      {
       "t": "text",
       "v": " claim returned by an OpenID Provider after MFA contain?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A list of scopes the resource server should enforce for this session"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A list of clients federated under the same trust framework as this IdP"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A list of methods used to authenticate, such as pwd, otp, or hwk"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A list of audiences the issued access token is permitted to talk to"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__200398",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What user-side material does a relying party store after WebAuthn registration?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It persists the raw biometric template returned by the authenticator"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It persists the public key and credential ID returned by the authenticator"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It persists the device PIN hash that unlocks the authenticator at use"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It persists the symmetric attestation secret returned by the authenticator"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__63721",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A TOTP server typically accepts codes within a +/- 1 step tolerance window. How many seconds does this allow for clock drift?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "30 seconds (only the exact current window)"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "300 seconds (10 full 30-second windows)"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "90 seconds, one 30-second step either side"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "60 seconds (two consecutive windows)"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__300415",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An auth product manager pushes back: 'WebAuthn is too hard. Our pilot saw 22% enrollment failure on roaming authenticators.' Logs show 'NotAllowedError' on the navigator.credentials.create call across multiple browsers. What is the most common cause of that error in practice?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "User agent rejected the request because the excludeCredentials list contained a credential ID that was already bound to that authenticator."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "User agent rejected the request because the relying-party identifier did not match the registrable domain suffix of the calling origin."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "User agent rejected the request because the requested algorithm list omitted ES256, which the platform requires for all create calls."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "User did not complete the user-verification gesture on the authenticator within the allotted ceremony timeout window set by the RP."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__429183",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing TOTP authenticator apps with SMS-based MFA, what is the primary security advantage of TOTP?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Codes are validated by the app server using the user's mobile number entry"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Codes are signed using the user's password as the HMAC key for binding"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Codes are generated locally on-device with no carrier network involvement"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Codes rotate every 60 seconds instead of 30 to give a wider validity range"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__104821",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "NIST SP 800-63B was revised (Rev. 4 finalized in 2025) to update guidance on the SMS factor. What is the current stance on SMS as a second factor?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Fully approved: equivalent to push notifications for AAL2 use cases"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Restricted: discouraged in favor of phishing-resistant factors like passkeys"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Required as a baseline factor for any authenticator at AAL2 assurance"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Banned outright: must be removed from every federal authentication deployment"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__318452",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "When a user signs in with a passkey synced across Apple/Google/Microsoft platforms, what assurance level does NIST SP 800-63B Rev. 4 (2025) currently allow such a credential to satisfy?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "AAL2: syncable passkeys meet AAL2, but AAL3 still requires a hardware-bound authenticator"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Not permitted at any AAL because the credential is not bound to a single physical authenticator"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "AAL1 only, because the private key material is replicated across the user's signed-in devices"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "AAL3: provided the platform attests the credential was generated by a secure element on device"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__63566",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why is FIDO2/WebAuthn considered phishing-resistant while TOTP is not?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "TOTP codes are visible in browser history"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The authenticator checks origin before signing"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "FIDO2 requires a cellular network connection"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "FIDO2 uses longer codes that are harder to guess"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__20512",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An app sends OTP codes via email. Why is email-based OTP generally considered weaker than app-based TOTP?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Email servers do not support TLS, so codes are always transmitted in cleartext over the wire"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "App-based TOTP requires a hardware security key, making it inherently stronger than email OTP"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Email accounts may only be password-protected, creating a single-factor dependency chain"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Email OTPs cannot be time-limited and therefore remain valid indefinitely after delivery"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__63810",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A TOTP code generated at 10:00:00 AM is entered at 10:01:15 AM (75 seconds later). The server uses a 30-second window with +/- 1 step tolerance. Is the code accepted?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "No, TOTP codes are invalidated the instant the 30-second window ends"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Yes, the tolerance window is 3 full minutes by default"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Yes, the server accepts any code generated in the last 5 minutes"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "No, 75 seconds spans 2.5 steps, beyond the +/- 1 step tolerance"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__65223",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "When checking permissions at runtime in Node.js 22+, what does "
      },
      {
       "t": "code",
       "v": "process.permission.has('fs.read', '/secrets/key.pem')"
      },
      {
       "t": "text",
       "v": " return?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An object with { allowed: boolean, reason: string }"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It throws an error because path-specific checks are not supported"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A Promise that resolves to the file contents if permitted"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A boolean indicating whether the current permission model allows reading that specific file path"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__65222",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "You run "
      },
      {
       "t": "code",
       "v": "node --permission --allow-fs-read=/app/data/* app.js"
      },
      {
       "t": "text",
       "v": ". An attacker creates a symlink "
      },
      {
       "t": "code",
       "v": "/app/data/escape -> /etc/passwd"
      },
      {
       "t": "text",
       "v": ". Can they read /etc/passwd?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "No, symlinks are automatically disabled when --permission is active"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "No, the permission model resolves symlinks before checking permissions"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Yes, symlink chains can escape the permitted path boundary; this is a known limitation of the Node.js permission model"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Yes, but only if the --allow-symlinks flag is also passed"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__200305",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes how a sudoers entry relates to least privilege?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It allows a named user to assume root access only after a second engineer types an approval code at the same console."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It allows a named user to inherit the union of all groups they have been added to since the host was first provisioned."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It allows a named user to switch to any other account on the host as long as that target account has a login shell."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It allows a named user to run only specific commands with elevation, leaving the rest of root power unreachable."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__65468",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How does DPoP (Demonstration of Proof-of-Possession) improve token security beyond standard bearer tokens?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It binds tokens to client key pairs so a stolen token cannot be replayed from a different client"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It rotates the token automatically every 30 seconds using a time-based algorithm"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It requires biometric authentication each time the token is presented"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It encrypts the token payload so only the intended API can decrypt and validate it"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__10212",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How should database permissions be modeled for microservices?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "One shared superuser credential across all services"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Read-write access to every schema used for debugging"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Privilege assigned by team instead of runtime identity"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Per-service identities with narrowly scoped grants per operation"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__65254",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "ABAC (Attribute-Based Access Control) offers finer-grained control than RBAC. What kind of attributes does ABAC use for authorization decisions?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The HTML data attributes present on the page element the user is trying to reach"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The caller's source IP address and browser user-agent string, and nothing beyond that"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Any combination of user attributes, resource attributes, environment conditions, and action types"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Just the caller's assigned role name, which ABAC reads as a single attribute value"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__65137",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "In a cloud environment, what does an IAM policy with "
      },
      {
       "t": "code",
       "v": "\"Action\": \"s3:\""
      },
      {
       "t": "text",
       "v": " and "
      },
      {
       "t": "code",
       "v": "\"Resource\": \"\""
      },
      {
       "t": "text",
       "v": " violate?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The principle of fail-safe defaults, because it allows public access"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The principle of least privilege, because it grants all S3 actions on all buckets"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The principle of separation of duties, because it combines two roles"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The principle of defense in depth, because it skips encryption"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__1916285",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A dev sets readOnlyRootFilesystem: true on a pod, expecting writes to fail everywhere. The app still writes log files to /var/log and an attacker plants a binary in /tmp that survives until pod restart. Why?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Volume mounts and emptyDir paths remain writable; only the image's root layer becomes read-only under that field"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The kubelet remounts /tmp and /var as tmpfs after pod start, which silently re-enables write access regardless of the security flag"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "readOnlyRootFilesystem applies only to the entrypoint process, so any forked child re-acquires write access to the original FS"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Containerd ignores the flag when the runtime class is the default runc, which is why writes to bind-mounted host paths succeed"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__200402",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes a just-in-time privilege elevation workflow?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A principal authenticates once with a hardware key whose presence is then sufficient to perform any elevated action."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A principal requests temporary elevated rights through an approval flow and the rights expire automatically after use."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A principal holds standing elevated rights and the system periodically forces a re-authentication to confirm presence."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A principal pre-provisions a shadow account whose elevated rights it copies in for a session and reverts at logout."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__682341",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Inside this pod, what does "
      },
      {
       "t": "code",
       "v": "cat /proc/self/status | grep CapEff"
      },
      {
       "t": "text",
       "v": " show after the runtime applies the spec?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "# pod.yaml (snippet)\nspec:\n  containers:\n  - name: app\n    image: alpine\n    command: [\"sleep\",\"3600\"]\n    securityContext:\n      capabilities:\n        drop: [\"ALL\"]\n      runAsNonRoot: true\n      runAsUser: 1000",
    "label": "least-privilege.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "CapEff: 0000000000000000"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "CapEff: 0000000000000400"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "CapEff: 00000000a80425fb"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "CapEff: 0000003fffffffff"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__310035",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Given the snippet logging key usage, what value does console.log print for the redacted key field?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "// node 20\nfunction redact(k) {\n  const [scheme, env] = k.split('_');\n  return `${scheme}_${env}_***${k.slice(-3)}`;\n}\nconsole.log(redact('sk_live_abc123def456'));",
    "label": "api-keys.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "sk_***_abc456"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "sk_live_abc***"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "sk_live_***456"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "***live_abc456"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__63744",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Using Clerk's M2M authentication, how does a backend verify an incoming API key on a request?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "const { isSignedIn } = await authenticateRequest(req, {\n  acceptsToken: 'api_key'\n});",
    "label": "api-keys.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Calling a third-party key validation service via webhook"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Calling authenticateRequest with acceptsToken 'api_key'"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Comparing the raw API key string against a local database table"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Decoding the API key as a JWT and verifying its signature locally"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__310052",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Given the snippet using Node's scrypt to derive a verifier from an API key for storage, what does console.log print for output.length when keylen=32?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "// node 20\nimport { scryptSync } from 'crypto';\nconst out = scryptSync('sk_live_abc123', 'salt-fixed', 32);\nconsole.log(out.length);",
    "label": "api-keys.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "64"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "48"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "16"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "32"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__156783",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing API-key auth via the Authorization header vs via a query-string parameter, what is the security argument against the query-string form?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Query strings cannot be transmitted over TLS-protected HTTPS connections at all"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Query strings are stripped by every modern HTTP client library before transmission"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Query strings collide with form-encoded body fields and silently overwrite them"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Server access logs and proxy logs typically capture the full request URL"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__310044",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Given the snippet caching a key→userId map in process memory for 60s, what behavior does console.log print after the key is revoked at t=10s and called at t=30s?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "// node 20\nconst cache = new Map();\nfunction auth(k, now) {\n  const e = cache.get(k);\n  const hit = e && now - e.ts < 60_000;\n  return (hit ? ['stale', 'accept'] : ['cache', 'miss', 'db']).join('_');\n}\ncache.set('sk_live_x', { userId: 1, ts: 0 });\nconsole.log(auth('sk_live_x', 30_000));",
    "label": "api-keys.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "expired_purge"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "stale_accept"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "fresh_reject"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "cache_miss_db"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__310032",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Given the snippet enforcing a per-key token bucket, what does console.log print after the 6th call within the same second when capacity is 5?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "// node 20, simple token bucket\nlet tokens = 5;\nfunction call() {\n  if (tokens <= 0) return 429;\n  tokens -= 1;\n  return 200;\n}\nlet last;\nfor (let i = 0; i < 6; i++) last = call();\nconsole.log(last);",
    "label": "api-keys.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "503"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "200"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "403"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "429"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__50373",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the security rationale for scoping API keys to specific endpoints and operations rather than granting broad access?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Scoped keys automatically expire faster than broad-access keys"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Scoped keys are computationally faster to validate than broad-access keys"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A compromised key reaches only the resources it was scoped to"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Broad-access keys cannot be stored in secrets managers due to size limits"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__63589",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the purpose of prefixing API keys with identifiers like 'sk_live_' or 'pk_test_'?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "To make the encoded token shorter for transmission over the network"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "To encrypt the token body with a cipher selected by the prefix value"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "To ensure the encoded token is compatible with every programming language runtime"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "To identify the key's type and environment without exposing the secret portion"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__200338",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How should a server persist a freshly issued API key?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Stored alongside the user's session row for fast log-in lookups"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Stored in plaintext under a row-level access control policy"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Stored as a one-way hash, similar to how passwords are kept"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Stored encrypted with a column key reversible by any backend service"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__63967",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How should API keys be stored server-side?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Store the hash of the key, never the plaintext"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Base64-encoded in the application's configuration file"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Encrypted with a key derived from the API key itself"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "In plaintext, for fast comparison at the API edge"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__77427",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "You're building a provenance verification library. A SLSA provenance attestation is wrapped in a DSSE envelope. What is the correct order of verification steps?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "1. Verify the Rekor entry exists, 2. Decode the DSSE envelope, 3. Check the signature matches the Rekor record"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "1. Verify the DSSE envelope signature, 2. Decode the base64 payload to get the in-toto statement, 3. Verify the predicate's claims (source, builder, subject digest) against expected values"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "1. Check the builder.id field, 2. If trusted, verify the signature, 3. If valid, check the subject digest"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "1. Decode the payload first, 2. Check the predicate claims, 3. Verify the signature last as a final validation"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__54142",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "PyPI maintainers move to Trusted Publishers much faster than they wire up Sigstore attestation generation. What does the asymmetry reveal about how teams perceive the two changes?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Trusted Publishers eliminates a concrete credential-theft risk on the publisher's side, while attestation generation only pays off when downstream consumers verify"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Attestation generation requires a paid PyPI organization plan, while Trusted Publishers is part of the free tier project configuration available to anyone"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Trusted Publishers signs the tarball during upload, so the attestation is implicit and counted separately from any explicit predicate uploaded by the maintainer"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Attestation generation is gated on the package being indexed by a major SBOM database before PyPI will accept the predicate from the publisher's workflow"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__77417",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "You want to verify npm provenance for all packages in your project programmatically. Which approach provides the most comprehensive verification?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Parse the lockfile and manually query the Rekor API for each package's transparency log entry one by one"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Run "
       },
       {
        "t": "code",
        "v": "npm audit signatures"
       },
       {
        "t": "text",
        "v": " which verifies both registry signatures and provenance attestations for all installed packages"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Scrape each package's npmjs.com page and detect the provenance badge directly in the rendered HTML markup"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Run "
       },
       {
        "t": "code",
        "v": "npm pack --dry-run"
       },
       {
        "t": "text",
        "v": " against every dependency to inspect its provenance before allowing installation"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__53893",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What command verifies the provenance and registry signatures of all packages installed in a Node.js project?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "npm audit --signatures-only"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "npm check signatures"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "npm audit signatures"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "npm verify --all"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__77603",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A maintainer publishes an npm package from their local machine (no provenance) and from CI (with provenance) for different versions. How does this inconsistency affect consumer trust?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "npm automatically blocks installation of any version that lacks provenance as soon as a single version of the package has ever been published with provenance attached to it"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Versions without provenance can't be verified, creating a trust gap. Consumers should prefer versions with provenance and investigate why some versions lack it - it could indicate a compromised local publish"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The absence of provenance on even a handful of versions retroactively invalidates the provenance attestations attached to every single other version of that same package"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Provenance is purely optional metadata, so its absence on some versions carries no security implications whatsoever and is never worth a consumer's time to investigate further"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__53936",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What provenance information can you verify by running "
      },
      {
       "t": "code",
       "v": "npm audit signatures"
      },
      {
       "t": "text",
       "v": " on a project?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Whether each installed package has a valid registry signature or Sigstore provenance attestation"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Whether each package's source code matches a known-good hash in a government database"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Whether each package maintainer has enabled two-factor authentication"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Whether each package's license is compatible with your project's license"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__200974",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing 'cosign verify' with 'cosign verify-attestation' on a container image, what does the latter additionally let the caller do?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Force the registry to rebuild the image from a pinned source commit"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Skip Rekor lookups and verify entirely from cached local material"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Reject the image whenever its registry tag has been moved recently"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Filter on a predicate type and inspect the embedded claim payload"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__53931",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is 'keyless signing' in the context of npm provenance?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Using short-lived certificates from an OIDC identity instead of long-lived private keys"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Publishing packages without any cryptographic signature at all"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Using the npm registry's master key to sign packages on behalf of publishers"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Generating a one-time key pair that is immediately destroyed after signing"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__53937",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What prevents a malicious actor from generating a fake provenance attestation for an npm package?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Fulcio only issues signing certificates to verified CI identities, and all certificates are recorded in Rekor's tamper-evident log"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Provenance attestations are encrypted with npm's master key so only the registry can create them"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "GitHub Actions blocks any workflow that attempts to publish without a code review approval"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "npm verifies the publisher's email address before accepting any provenance data"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__54148",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does a PyPI Publish Attestation (v1) allow consumers to verify?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "That a specific release distribution was uploaded via a Trusted Publisher, and exactly which identity did it"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "That the package's setup.py and pyproject.toml were validated against PyPI's static-analysis ruleset before upload"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "That the project's repository has branch protection enabled on the branch where the build was triggered from"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "That every transitive Python dependency was rebuilt from source inside the Trusted Publisher's workflow environment"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__200343",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does the script output?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "rows = [\n  {'age': 400, 'hold': False},\n  {'age': 500, 'hold': True},\n  {'age': 800, 'hold': False},\n  {'age': 100, 'hold': False},\n]\nttl = 365\ncount = sum(1 for r in rows if r['age'] > ttl and not r['hold'])\nprint(f'{count} records purged')",
    "label": "data-retention.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "0 records purged"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "3 records purged"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "1 records purged"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "2 records purged"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__300453",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes how GDPR's right to erasure (Article 17) interacts with documented retention obligations under other law?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A controller may refuse erasure where processing is necessary for compliance with a legal obligation requiring retention."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A controller must seek explicit supervisory-authority approval before declining any erasure request on retention grounds."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A controller must always honour erasure within thirty days regardless of other statutory retention obligations that apply."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A controller must transfer the record to an offline vault when a competing retention obligation prevents direct deletion."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__700501",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your team operates an event-sourced ledger as the system of record. The auditor asks how DSAR-erasure is implemented when events are by design immutable. The CTO proposes appending a 'redacted' event that overlays nulls at projection time. A second auditor calls this insufficient. What is the precise weakness?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The projection rebuild on a fresh consumer applies the overlay later than read traffic expects within the SLA window"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The raw event log still contains the PII at rest, so backup or operator access bypasses the projection-time overlay"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The projection overlay relies on a deterministic ordering that the ledger does not guarantee under partition recovery"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The redacted event creates a new replay path that violates the append-only invariant of the underlying ledger"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__100253",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What's the difference between 'soft delete' and 'hard delete' in the context of a GDPR right-to-erasure request?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Soft delete preserves referential integrity by leaving foreign keys intact; hard delete cascades to all child records but requires a separate legal sign-off"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Soft delete is reversible within a 30-day window; hard delete is irreversible and must therefore be approved by the DPO before the deletion job runs"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Soft delete sets a deleted_at flag but the row is still present; hard delete removes the row so it cannot satisfy an Article 17 erasure on its own"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Soft delete archives the row to a cold table for analytics; hard delete is the only state where the regulator considers the data fully out of the controller's possession"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__200345",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does it print?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "policy_loaded = True\ndry_run = False\nif policy_loaded and not dry_run:\n    state = 'deletion_job_armed'\nelif policy_loaded and dry_run:\n    state = 'deletion_job_paused'\nelse:\n    state = 'deletion_job_failed'\nprint(state)",
    "label": "data-retention.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "deletion_job_armed"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "deletion_job_undone"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "deletion_job_failed"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "deletion_job_paused"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__200329",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Choosing between 'anonymisation' and 'pseudonymisation' for end-of-life user data under GDPR - what's the substantive trade-off?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Anonymised data falls outside GDPR scope but is irreversible; pseudonymised data is still personal data under GDPR because re-identification with the key remains possible"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Anonymised data still counts as personal data under recital 26; pseudonymised data is treated as fully out-of-scope once the mapping table sits in a separate vault entirely"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Anonymisation requires DPA pre-approval per member state; pseudonymisation is auto-approved as long as the linking key is held by a third-party processor with a DPA"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Anonymisation must be applied at collection time per Article 25; pseudonymisation can be applied at any time but only with renewed data-subject consent on each transformation"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__300452",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is logged?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "policy = {}\npolicy['logs'] = 365\npolicy['audit'] = 365 * 7\npolicy['pii'] = 365 * 2\nprint(policy)",
    "label": "data-retention.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "{'logs': 365, 'audit': 730, 'pii': 2555}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "{'logs': 730, 'audit': 365, 'pii': 2555}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "{'logs': 365, 'audit': 2555, 'pii': 730}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "{'logs': 2555, 'audit': 365, 'pii': 730}"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__400559",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing 'expire data via lifecycle rule' (S3 lifecycle, BigQuery table expiration) with 'delete data via application logic' - which is the more defensible primary control for sensitive personal data?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Application logic and lifecycle rules are equivalent: the regulator allows whichever produces a deletion confirmation event in the platform's central activity log inside the same window"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Lifecycle rules are the only auditable option for object storage because application-layer deletes do not survive object-version pruning across the cloud provider's storage tiering"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Lifecycle rules are preferred because the cloud provider attests to the deletion in its SOC 2 report, removing the need for a separate application-layer attestation by the controller"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Application logic gives per-record decisions tied to user actions and legal-hold state; lifecycle rules are coarse-grained and indifferent to per-subject exceptions like holds or DSARs"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__400562",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A GDPR erasure request must remove a user's PII while analytics tables keep valid foreign-key references to the user id. Which end state satisfies both requirements?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "raw retained; tombstone written"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "tombstone written; raw deleted"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "raw retained; tombstone skipped"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "tombstone skipped; raw deleted"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__700203",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A daily job logs: 'Erasure batch: 412 user rows purged, 0 audit entries purged'. Legal asks why audit rows survive the same purge run. What is the correct reasoning to surface?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Audit logs run on a separate retention domain tied to regulatory minimums, not the user-record TTL"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Audit log rows reference the user row by FK, so the cascade requires a two-phase delete the batch skips"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Audit log writes are queued through a different broker that the erasure batch has no producer rights against"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Audit log rows include a tamper-evident hash chain that blocks individual row deletion by design"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__200341",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A dev satisfies an erasure request by setting users.deleted_at = now() and filtering deleted rows from queries, expecting GDPR compliance. The auditor flags it. What's the actual gotcha?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Soft delete is only valid when the deleted_at column is itself encrypted with a per-user key"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Soft delete leaves identifiable PII at rest, which still counts as processing under GDPR"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Soft delete needs to fire a Kafka event so downstream analytics warehouses also mark the row"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Soft delete must instead set a tombstone hash so foreign-key joins keep returning the row"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__200005",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing 'data controller' with 'data processor' under GDPR, who decides what counts as the controller in a SaaS arrangement?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The controller is the entity whose name appears on the SOC 2 report; the processor is the entity audited under a SOC 1 report"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The controller determines purposes and means of processing; the processor acts only on documented instructions from the controller"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The controller is whichever entity holds more than 50% of the data records at rest; the processor is whichever entity holds the remainder"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The controller is the encryption-key custodian; the processor is whichever party hosts the database cluster regardless of decision rights"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__200346",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An analytics SDK is added to the checkout page. Within a week, the cookie-banner vendor's report shows the SDK firing before the 'Accept' button is clicked. Which of Cavoukian's seven foundational principles was violated?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Visibility and transparency: the cookie policy fails to enumerate every recipient"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "User-respect: the consent banner lacks a granular per-purpose toggle for analytics"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "End-to-end security: the analytics payload is sent over a downgraded TLS channel"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Privacy as the default setting: no non-essential processing until the user opts in"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__31182",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A privacy team adopts a privacy threat model (e.g., LINDDUN) alongside an existing STRIDE-based security threat model. What does the privacy model add that STRIDE alone does not surface?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Threats whose harm is credential reuse across tenants, not credential theft at the auth boundary"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Threats whose harm is supply-chain compromise during build, not runtime tampering at the host"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Threats whose harm is service availability under burst load, not steady-state denial of service"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Threats whose harm is contextual norm-violation or profiling, not just confidentiality, integrity, or availability"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__300420",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A signup flow makes account creation conditional on marketing consent that is not necessary for performing the contract. How does a GDPR Article 7 check classify this consent?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "invalid:not_freely_given"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "invalid:not_unambiguous_act"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "invalid:bundled_purposes"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "valid:withdrawn_too_late"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__400003",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the GDPR Article 22 right concerning automated decision-making?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A right to demand a human-in-the-loop review for every automated decision that affects pricing, eligibility, or service delivery."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A right to obtain a written explanation of the variables, weights, and feature engineering used by any production scoring model."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A right to have any model trained on personal data retrained from scratch after exercising erasure under Article 17."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__17157",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An EM weighs two designs for a new behavioural-analytics feature: design A collects every event a user generates; design B collects only events tied to documented product-improvement hypotheses. Under Art. 5(1)(c), how should the design review treat 'we might need it later for ML' as a justification for A?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Accept it if a future DPIA is committed to once the ML feature scope is firmed up"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Reject it: Art. 5(1)(c) requires the necessity test at the time of collection, not retrospectively"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Accept it if the controller commits to anonymising A's events on a documented schedule"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Accept it if A's events are stored in an environment isolated from production identifiers"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__300417",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A pipeline replaces each customer email with a deterministic HMAC-SHA256 token, and the operator keeps the HMAC key. How does GDPR treat the resulting records?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "no_longer_personal_data:anonymised"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "still_personal_data:pseudonymised"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "no_longer_personal_data:tokenised"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "still_personal_data:encrypted_only"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__400517",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A bank's scoring model alone determines credit-line eligibility, with no human involved in the outcome. Which GDPR breach does an audit of this flow flag?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "violation:art22_solely_automated_decision"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "violation:art13_notice_not_provided"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "violation:art15_access_not_provided"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "violation:art21_objection_not_honoured"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__934817",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A 2025 DPIA covers a feature that profiles users to recommend learning paths. Following recent EDPB guidance on automated decision-making, what does the DPIA need to capture beyond what 2023 templates typically included?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A signed waiver from each profiled user acknowledging the limits of model explainability"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A line-by-line copy of the recommendation model's source code archived with the DPIA"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A weekly metric of profiled users grouped by GDPR special-category data they generated"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A meaningful explanation of the logic, significance, and envisaged consequences of the profiling"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__65338",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is tamper-evident logging, and why does it matter for forensic integrity?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Logs are stored in append-only databases that prevent any reads after writing"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Each log entry is cryptographically chained to the previous one (hash chain), so any modification or deletion of entries is detectable"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Logs are written to a blockchain network, making them publicly verifiable by anyone"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Each log entry is signed with the application's TLS certificate, proving the server's identity"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__384716",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "After this snippet, what string is logged for the "
      },
      {
       "t": "code",
       "v": "Authorization"
      },
      {
       "t": "text",
       "v": " header value?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "import pino from 'pino';\nconst log = pino({ serializers: { headers: (h) => ({ Authorization: h.Authorization.slice(0,18) + '...truncated' }) } });\nlog.info({ headers: { Authorization: 'Bearer eyJhbGciOiJIUzI1NiJ9.payload.sig' } });",
    "label": "logging-security.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Bearer eyJhbGc<token-strip>"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Bearer eyJhbGciOiJI...REDACT"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Bearer eyJhbGciOiJ...truncated"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Bearer eyJhbGciOiJIUzI1NiJ9"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__815394",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the redact option in pino?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It accepts a list of log levels that should be suppressed entirely from the configured destination"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It accepts a list of regex patterns matched against the network address of every downstream sink"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It accepts a list of property paths that should be replaced or removed from the serialized output"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It accepts a list of file paths whose contents are encrypted before the log shipper forwards them"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__10254",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which access policy should govern security-log stores compared to generic application logs?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Self-service portal where users can view logs about themselves"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Open read access for any internal service account on the network"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Same broad read access granted to every product engineer"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Strict least privilege with monitoring and retention"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__10172",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which category of data must be redacted before it reaches a structured-log sink?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Passwords, session tokens, and private keys"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Correlation identifiers, span identifiers, and HTTP methods"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Authentication outcome codes, retry counts, and source IPs"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Service version tags, region labels, and deployment build IDs"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__1156372",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A GDPR DSAR request requires deleting all logs for user 4471 within 30 days. Logs ship via Fluent Bit to S3 archives, the SIEM (Splunk), an analytics warehouse (BigQuery), and a vendor error tracker. The team's only redact rule lives in the app's pino config. Why does this DSAR scenario fail in practice?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "S3 lifecycle rules cannot honour single-user DSARs and require global expiry across the bucket prefix tree"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "GDPR exempts security logs entirely so the team only needs to redact the analytics warehouse for the DSAR"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Splunk forwarder masking strips PII once but the warehouse copy retains the unmasked entries by replication"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Each downstream sink retains its own copy and redaction at source does not retroactively scrub already-shipped data"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__729184",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes how winston's format pipeline supports keeping secrets out of records?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Transports validate each outgoing line against an allowlist of permitted log levels at runtime"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The default JSON format encrypts marked fields automatically using the configured logger secret"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Custom formatters can rewrite or drop fields on the info object before any transport receives it"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The logger refuses any field whose serialized representation exceeds a configured byte budget"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__65080",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is tamper-evident logging, and what technique makes it possible?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Logs signed with the application's TLS certificate before storage"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Append-only logs with cryptographic chaining, where each entry includes a hash of the previous entry"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Logs encrypted with a public key that only the security team can decrypt"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Logs stored on a read-only filesystem with daily rotation"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__65139",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "If you must log user-identifiable information for security analysis, what technique should you use?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Anonymization - permanently strip every identifying field so the records can never be re-linked"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Pseudonymization - replace direct identifiers with reversible tokens that require a separate key to resolve"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Truncation - retain only the first three characters of each identifier and discard the rest"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Tokenization - store the identifiers on a blockchain ledger so that they become tamper-evident"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__381947",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What value appears under the "
      },
      {
       "t": "code",
       "v": "authorization"
      },
      {
       "t": "text",
       "v": " key in the emitted JSON line?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "import pino from 'pino';\nconst log = pino({ redact: { paths: ['headers.authorization'] } });\nlog.info({ headers: { authorization: 'Bearer abc123', host: 'x' } });",
    "label": "logging-security.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "code",
        "v": "<omitted>"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "[Redacted]"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "code",
        "v": "<hidden>"
       },
       {
        "t": "text",
        "v": ">"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "*masked"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__402735",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Distinguishing a Rekor inclusion proof from a basic signature check during cosign verification, what role does the proof play?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It pre-resolves a dependency graph of the artifact's transitive base images so the policy can rescan each layer"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It demonstrates the signing event was recorded in the public log so retroactive denial of the event is detectable"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It rewraps the certificate's private key for short-term escrow so a second verifier can re-sign on demand later"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It re-derives the artifact digest from the layers fetched and confirms the registry returned the expected blob set"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77283",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the purpose of cosign's "
      },
      {
       "t": "code",
       "v": "--certificate-chain"
      },
      {
       "t": "text",
       "v": " flag during verification?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It exports the full certificate chain that cosign used during the most recent signing operation to a local file path for offline archival or downstream replay"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It provides intermediate CA certificates needed to build the trust chain from the signing certificate to a trusted root"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It explicitly defines the order in which multiple cosign signatures attached to the artifact should be evaluated when verifying against a layered admission policy"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It specifies multiple independent signing certificates that cosign should accept as valid for the same artifact during a multi-party verification workflow"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77674",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the difference between cosign sign (simple signature) and cosign attest (attestation)?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "cosign sign targets container images while cosign attest is the dedicated entry point for signing non-container artifact types such as raw binaries, SBOM files, and other on-disk blobs"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "cosign sign creates a bare signature proving the artifact's authenticity. cosign attest creates a signed in-toto statement containing structured metadata (provenance, SBOM, scan results) about the artifact"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "cosign attest produces several independent signatures over the artifact for redundancy while cosign sign produces just one signature computed over the artifact's content digest"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "cosign sign uses Fulcio's keyless certificate authority while cosign attest delegates its signing to a separate certificate authority that is configured per attestation predicate type"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77273",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "You sign a Helm chart that is published as an OCI artifact using cosign. How is the resulting signature stored and distributed alongside the chart?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The signature is materialized as a Kubernetes Secret in the namespace where the chart will be installed, and the Helm controller reads that Secret before reconciling the release manifest"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The signature is pushed as a separate OCI artifact in the same registry, referencing the Helm chart's OCI manifest digest via the cosign tag or referrers convention"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The signature is serialized into the Chart.yaml metadata as a top-level "
       },
       {
        "t": "code",
        "v": "signature"
       },
       {
        "t": "text",
        "v": " field, so helm pull and helm install can read it directly from the chart archive at install time"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The signature is written to a sibling .prov file generated by the built-in helm package --sign flow, and cosign verify reads the .prov GPG signature instead of producing its own"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77258",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your team uses cosign with a key pair (not keyless) stored in a cloud KMS. When rotating the signing key, how do you handle images signed with the old key?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Rely on cosign to automatically migrate prior signatures the moment it detects a new key version in the same KMS key ring used during the original signing operation"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Keep the old public key in your verification policy alongside the new one, accepting signatures from either key during the transition period"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Treat all signatures from before the rotation as immediately invalid and force a complete redeployment of every image, replacing every signature with one from the new key"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Re-sign every existing image with the freshly rotated key before removing the previous key version from the KMS key ring used by the cosign signing pipeline"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__300458",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes what the SAN (Subject Alternative Name) extension on a Fulcio cert encodes?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The Rekor log shard endpoint where the certificate's signing event will be persisted later"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The artifact digest that the signer is committing to and binding into the certificate chain"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The OCI registry hostname authorized to receive the resulting signature manifest blob upload"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The signer's OIDC identity such as an email, GitHub workflow URI, or SPIFFE ID"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__651982",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why does this verification fail even though the package is published with provenance?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "# package built from github.com/acme/widget\ncosign verify-attestation \\\n  --type slsaprovenance \\\n  --source-repository-url https://github.com/acme/wodget \\\n  --certificate-oidc-issuer https://token.actions.githubusercontent.com \\\n  --certificate-identity-regexp '.+' \\\n  registry.npmjs.org/widget@1.0.0",
    "label": "artifact-signing.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Public registry tarballs strip provenance metadata once a package is downloaded by clients"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Provenance attestations are only verifiable through npm audit signatures, never via cosign"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The expected source repo URI does not match the one recorded in the attestation subject"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Cosign cannot read npm provenance bundles because they use a different envelope wrapper"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77559",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "When you run "
      },
      {
       "t": "code",
       "v": "cosign verify"
      },
      {
       "t": "text",
       "v": " and it succeeds, what minimum information is displayed?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The verified signatures with the signing identity (certificate subject/issuer), confirming who signed the image and when"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Only a terse 'Verified OK' status string with no further detail about the underlying signer identity, certificate, or transparency log entry on the standard output stream"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The complete software supply chain provenance from the original source commit, through the build pipeline, all the way to the signed deployed image artifact metadata"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A summary of the most recent vulnerability scan run against the verified container image, listing each detected CVE alongside its current upstream remediation status now"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77279",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "You're evaluating the security of Fulcio's certificate issuance. An attacker obtains a valid OIDC token for your CI identity (e.g., through a GitHub Actions token scope escalation). What prevents them from getting a Fulcio certificate that persists beyond the 10-minute window?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Fulcio certificates are hard-coded to a short validity period and cannot be extended. Whoever holds the token can sign only in those minutes, and Rekor records the signing event"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The Fulcio certificate authority requires mutual TLS with a pre-registered client certificate from each CI system before it will issue a signing certificate"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Fulcio rate-limits certificate issuance to a maximum of one short-lived certificate per identity per hour, which bounds how many artifacts a single stolen token can sign across the fleet it protects"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Fulcio inspects the OIDC token's intended audience claim and rejects a token that does not explicitly request a certificate from this Fulcio instance on the request"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__54109",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What change in Cosign 2.0 removed the need for COSIGN_EXPERIMENTAL=1 when using keyless signing?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A new "
       },
       {
        "t": "code",
        "v": "COSIGN_KEYLESS=1"
       },
       {
        "t": "text",
        "v": " environment variable replaced the older experimental flag, and cosign still requires it to be explicitly set before any keyless signing operation"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Cosign 2.0 now requires a paid Sigstore Enterprise subscription before any client can perform keyless signing against the public-good Fulcio and Rekor service instances"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Cosign 2.0 dropped keyless signing entirely in favor of requiring hardware-backed signing keys on every signing host that participates in the cosign signing workflow"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Identity-based signing and Rekor transparency logging are now enabled by default"
       }
      ],
      "shape": "short"
     }
    ]
   }
  }
 ]
}
