{
 "schemaVersion": 1,
 "pathSlug": "soc2-operator",
 "items": [
  {
   "questionId": "compliance.soc2_basics__200103",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the correct characterization of a SOC 2 Type 1 report?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An auditor opinion on whether controls are suitably designed as of a single point in time"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "An auditor opinion on whether controls operated effectively over a defined review period of months"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A continuous monitoring artifact streamed from compliance automation platforms to customers"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A management self-assessment of control design completed before any audit fieldwork begins"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__17201",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Access review control is documented annually but never executed. Which gap is present?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An operating-effectiveness gap: the control is suitably designed on paper but did not operate at its stated cadence during the period"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A scoping gap: an unperformed access review should be carved out of the system description entirely"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A design gap: the documented control would fail to meet CC6 even if it had been performed on schedule"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A documentation gap: the policy text needs rewording before the auditor will accept the missing reviews"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__50998",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An engineering team is choosing between Drata, Vanta, and Secureframe for SOC 2 readiness. What dimension matters most in the selection?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Whether the platform shares an investor with the CPA firm engaged to issue the final SOC 2 opinion"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Whether the platform brands itself as enterprise-grade in its marketing material and customer reference list"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Whether the platform offers the highest count of pre-built policy templates regardless of integration depth"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Whether the platform's integration catalog covers the entity's actual stack (cloud, IdP, code host, HRIS, ticketing) for automated evidence"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__17148",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Two SaaS teams have similar policies. Team A maintains an owner-mapped control matrix; Team B does not. Which audit-cycle outcome does Team A typically achieve?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A faster path to an unqualified opinion, because owner-mapped controls are reviewed less rigorously than orphaned ones"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Repeatable evidence collection across periods, because each control names an accountable owner and a deterministic evidence source"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Exemption from sampling, because owner attestation removes the auditor's need to test per-instance evidence in the window"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A reduced count of Common Criteria in scope, because mapped controls collapse adjacent CC families during fieldwork"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__100001",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A startup is choosing between a SOC 2 Type 1 and a SOC 2 Type 2 report for its first audit. What is the core distinction between the two report types?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Type 1 covers only the Security criterion at a point in time; Type 2 adds Confidentiality and Privacy across the same single date assessment"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Type 1 attests to control design at a single point in time; Type 2 attests to operating effectiveness over a period (typically 6-12 months)"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Type 1 is issued by the company itself; Type 2 requires a CPA firm to attest to the same controls without any extended period of review"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Type 1 requires Drata or Vanta automation evidence; Type 2 permits manual evidence collection across the full audit window without tooling"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__31199",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How does vendor management relate to SOC 2 compliance, and what due diligence is required for third-party service providers?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Vendor management in SOC 2 only applies to direct competitors; business partners are considered trusted by default"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Vendors are entirely responsible for their own SOC 2 compliance; the customer organization has no related obligations"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 requires assessing third-party vendors' security controls, reviewing their SOC 2 reports, maintaining contracts with security requirements, and monitoring vendor access"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 prohibits using cloud services like AWS or GCP since they introduce uncontrolled third-party risks"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__51003",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How does the DSA's transparency reporting requirement (effective July 2025) create new SOC 2 considerations for platforms?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 auditors are prohibited from reviewing DSA-related controls"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "DSA transparency reports can substitute for SOC 2 Type 2 audit reports"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The DSA eliminated all SOC 2 requirements for European platforms"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Platforms must implement auditable processes for content moderation reporting, which can provide evidence for multiple SOC 2 Trust Services Criteria including security and processing integrity"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__400021",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How does the AICPA's SOC 2 framework differ from the AICPA's SOC for Cybersecurity (SOC-C) in target audience and scope?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 attests to a service organization's controls for use by its customers; SOC for Cybersecurity reports on an entity's enterprise-wide cybersecurity risk program for broader stakeholders"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 is delivered orally to internal stakeholders only; SOC for Cybersecurity is the written equivalent for the same internal audience under the same AICPA reporting standard"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 is a checklist self-assessment without auditor involvement; SOC for Cybersecurity is the auditor-validated form of that same checklist for the same service-organization audience"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SOC 2 is reserved for organizations under 500 employees; SOC for Cybersecurity is reserved for any organization above that headcount threshold operating any cyber program"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__300010",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A team has shipped controls and is choosing whether the first SOC 2 observation period should be three months versus a full twelve months. What is the trade-off between a shorter and a longer initial Type 2 period?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A shorter period yields a report sooner but with less operating evidence; a longer period builds stronger evidence but delays the first customer-shareable report"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A shorter period reduces the number of Trust Service Criteria the auditor must test; a longer period forces inclusion of every elective criterion regardless of customer demand"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A shorter period legally caps the auditor's opinion to a qualified one; a longer period guarantees an unqualified opinion regardless of how controls performed during testing"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A shorter period removes the requirement for a written management assertion; a longer period requires the assertion plus a separately signed CEO attestation document"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.soc2_basics__915327",
   "topic": "compliance",
   "subSkill": "soc2_basics",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An eng team runs "
      },
      {
       "t": "code",
       "v": "terraform destroy"
      },
      {
       "t": "text",
       "v": " on dev infra mid-audit, wiping CloudTrail history for an in-scope test account. The auditor flags it as a control failure under CC7. What's the underlying gap?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Logging infrastructure for in-scope systems must rotate retention windows monthly to satisfy AICPA log freshness rules"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Logging infrastructure for in-scope systems must be reviewed line-by-line by the engineering manager every audit week"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Logging infrastructure for in-scope systems must be hosted entirely on dedicated bare-metal outside the cloud tenant"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Logging infrastructure for in-scope systems must be protected from modification or destruction by the same users it monitors"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__403672",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Tabletop exercise: the scenario has ransomware encrypting the audit log store and the backup S3 bucket. The IR lead announces 'we restore from backup'. The compliance engineer pushes back on this single-line plan. What auditor-visible weakness are they pointing to?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Restoring overwrites forensic evidence and the chain-of-custody record needed for the breach assessment"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Restoring from backup is forbidden until law enforcement formally takes custody of the encrypted volumes"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Restoring from backup invalidates the SOC 2 control over backup integrity testing for the audit period"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Restoring from backup requires a separate disaster-recovery declaration before any restore command runs"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__17121",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "At 02:00 in an active breach, the engineering lead and the head of communications disagree about whether to email customers in the next hour. The runbook is silent on this. Which runbook element was missing?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The template language for customer-facing apology emails and the legal-team turnaround time on copy reviews"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The named decision-owner authorised to approve external comms and the trigger conditions for doing so"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The escalation contact for the cloud-provider account team and their preferred channel for ticket priority bumps"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The list of approved comms tooling vendors and the procurement steps to onboard a new vendor during outages"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__1379452",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A post-incident control-update tracker emits a SOC 2 evidence row. Given the incident dict, what is printed?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "def soc2_row(inc):\n    status = \"closed\" if inc[\"postmortem\"] else \"open\"\n    tag = \"cc7.5_satisfied\" if inc[\"control_updates\"] > 0 else \"cc7.5_unsatisfied\"\n    return (inc[\"id\"], status, inc[\"control_updates\"], tag)\n\nprint(f\"row={soc2_row({'id':'INC-42','postmortem':True,'control_updates':3})}\")",
    "label": "incident-response.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "row=('INC-42', 'closed', 0, 'cc7.5_unsatisfied')"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "row=('INC-42', 'open', 3, 'cc7.4_satisfied')"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "row=('INC-42', 'closed', 3, 'cc7.4_acknowledged')"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "row=('INC-42', 'closed', 3, 'cc7.5_satisfied')"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__51016",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What enforcement power does the European AI Office have for investigating incidents involving GPAI models?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "No enforcement power until member states complete their own investigations"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The ability to request documentation, conduct evaluations, demand source code access, and impose corrective measures"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Authority limited to requesting a written explanation within 90 days"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Only the power to issue non-binding recommendations to model providers"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__104736",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "HHS issued guidance in late 2024 reiterating HIPAA Breach Notification Rule timelines for breaches affecting 500+ individuals. By when must a covered entity notify HHS of such a breach?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Without unreasonable delay and in no case later than annually as part of the HIPAA wrap-up report"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Without unreasonable delay and in no case later than 30 calendar days after discovery of the breach"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Without unreasonable delay and in no case later than 60 calendar days after discovery of the breach"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Without unreasonable delay and in no case later than 72 hours after discovery of the breach event"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__1284037",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An IR escalation engine resolves the strictest external deadline for a breach impacting EU residents, US patients, and cardholder data. What is printed (hours)?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "deadlines = {\n    \"gdpr_authority\": 72,\n    \"hipaa_hhs_500plus\": 60 * 24,\n}\nstrictest = min(deadlines.values())\nprint(f\"strictest_external_deadline_hours={strictest}\")",
    "label": "incident-response.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "strictest_external_deadline_hours=72"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "strictest_external_deadline_hours=24"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "strictest_external_deadline_hours=60"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "strictest_external_deadline_hours=96"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__17120",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A security lead is choosing between an annual tabletop and an annual live drill to satisfy the 'plan tested' control. What is the differential value a tabletop delivers that a live drill does not?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Demonstrates that monitoring alerts fire correctly during a real chain of triggered detections and pages"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Validates that runbook commands execute correctly against the current state of production infrastructure"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Surfaces decision-authority and communication gaps cheaply because no production systems are touched"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Produces measurable mean-time-to-contain numbers that can be compared against prior live drill results"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__31203",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "During an active breach the team has isolated the compromised host and confirmed the malware family, but the same indicators reappear on a second host four hours later. Which NIST SP 800-61r2 phase did the team likely under-execute before declaring containment complete?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Detection and analysis, because the SIEM correlation rules failed to fire on the secondary host until manual review"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Eradication of the underlying cause across the affected environment, not only on the host where the indicator first surfaced"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Post-incident activity, because the lessons-learned meeting had not yet been scheduled by the incident commander"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Preparation, because the runbook for this malware family had not been reviewed since its last quarterly update cycle"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__200101",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "On detecting a confirmed breach affecting EU personal data, an on-call engineer immediately terminates the compromised EC2 instance to stop further data exfiltration, then opens a ticket to begin investigation. The consultant brought in the next morning reports there is nothing left to analyze. What did the engineer get wrong relative to a typical IR playbook?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The on-call should have filed a customer-facing notification before containment so affected parties learn of the breach from the company instead of media"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The on-call should have rotated the IAM credentials attached to the workload before any containment action so attacker persistence is severed first"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Termination destroyed volatile memory and ephemeral disk state before a snapshot or memory capture was taken to preserve evidence for the forensics step"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The on-call should have notified the supervisory authority before any containment action because GDPR requires regulator engagement to precede technical response"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.incident_response__915627",
   "topic": "compliance",
   "subSkill": "incident_response",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A test harness runs the IR plan tabletop frequency check. What is printed?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "MIN_IR_TABLETOP = \"annually\"\n\ndef plan_status(plan):\n    if not plan[\"documented\"]:\n        return \"plan_missing\"\n    return f\"tabletop_due={MIN_IR_TABLETOP}\"\n\nprint(plan_status({\"documented\": True}))",
    "label": "incident-response.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "tabletop_due=quarterly"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "tabletop_due=annually"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "tabletop_due=monthly"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "tabletop_due=biennial"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__200152",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the correct characterization of structured audit log fields?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Each event is enriched at read-time by a sidecar that infers fields from the message text body"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Each event is rendered as a human-readable prose sentence written by the application developer"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Each event has typed, named attributes so logs can be queried and filtered without text parsing"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Each event is serialized into a compact binary frame designed to minimize on-disk storage cost"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__17177",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An auditor reviews policy-edit entries and finds that each one records only that an edit happened, not what changed. Which forensic capability is most directly undermined?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Correlating the policy edit with related events across services"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Reconstructing the before-and-after state of the modified policy"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Identifying which downstream service first observed the edit"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Classifying the severity of each policy-edit event at ingestion time"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__471038",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "PCI DSS v4.0 became the only valid version for assessments in 2024. Which audit-logging requirement did v4.0 newly mandate beyond what v3.2.1 required?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Quarterly external vulnerability scanning of all logging infrastructure by an approved vendor"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Manual daily log review by a designated team member with sign-off in a ticketing system"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Automated log review mechanisms for daily review of security events across in-scope systems"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Annual penetration testing focused specifically on the centralised log aggregation pipeline"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__31162",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your team is designing the schema for an audit event covering a GDPR-relevant access to personal records. Which field set best balances accountability with the minimisation principle?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Only the principal and the resource field name; the actual values returned by the access must never appear"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Only delete operations are logged in audit; read and update activity stays in the application's operational logs"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A complete before-and-after snapshot of every record that the operation read, modified, or deleted at runtime"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Principal, UTC timestamp, action, resource identifier, data classification, purpose, and request context (IP, session)"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__17107",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "When designing an audit log for a system that handles regulated data, which event class returns the highest forensic value per byte stored?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Privileged access and permission changes"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Cache hit and miss counters from the edge layer"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Heartbeat pings from internal monitoring agents"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Every successful read of a public marketing page asset"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__200153",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the role of an immutable storage tier (e.g. S3 Object Lock) in audit logging?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It encrypts every uploaded object with a customer-managed key rotated monthly by the storage provider"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It compresses uploaded objects in place to keep retention budgets within the SOC reporting period"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It enforces retention by blocking overwrite and deletion of objects within the configured window"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It indexes uploaded objects by content hash so auditors can perform similarity searches at scale"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__17176",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An auditor notes that the production app role can edit and delete entries in the security event store. Which audit property has been violated?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Centralisation of the entries from multiple emitting services"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Confidentiality of the entries against unauthorised readers"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Integrity and tamper resistance of the stored entries"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Retention of the entries for the required regulatory window"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__17134",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your team wants the central audit store to give an auditor a defensible answer when asked 'could a privileged operator have rewritten a prior entry?'. Which design most directly supplies that answer?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Append-only storage with cryptographic integrity verification"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Weekly compression of older segments without integrity manifests"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Periodic copy of entries into long-form email summaries"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Disk-full triggered rotation that overwrites the oldest entries"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__1361784",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your SaaS supports US public-company customers in 2025. Their internal audit team cites SOX retention expectations for audit logs of financial-system-adjacent activity. Which retention horizon now anchors the contractual ask?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Five years of retention for events touching systems in scope for financial reporting controls"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Three years of retention for events touching systems in scope for financial reporting controls"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Seven years of retention for events touching systems in scope for financial reporting controls"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Ten years of retention for events touching systems in scope for financial reporting controls"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.audit_logging__200344",
   "topic": "compliance",
   "subSkill": "audit_logging",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A dev logs audit events as a single 'message' string like 'user u_123 changed role of u_456 from member to admin'. The auditor asks for a list of all role escalations to admin in the last quarter and the dev spends a day writing regex. What was the gotcha the dev missed up front?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Audit events should be emitted as plain text but indexed by a search engine like OpenSearch so regex queries run efficiently against the message body"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Audit events should be emitted as plain text but the actor and target ids must always appear in the same column position for log-shipper parsing"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Audit events should be emitted as structured fields (actor, action, target, before, after) so they can be queried without parsing free-text messages"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Audit events should be emitted as plain text but each message must begin with a fixed prefix tag so downstream consumers can filter by event class"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__400005",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best characterises 'sensitive authentication data' (SAD) versus cardholder data (CHD) under PCI-DSS?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SAD is the truncated representation kept for fraud analytics and is retained per the merchant's analytics policy."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "SAD (full track, CAV2/CVC2/CVV2/CID, PIN/PIN block) must not be retained after authorisation, even when encrypted."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SAD comprises the printed name, billing postcode, and expiry, and may be retained alongside the PAN if encrypted."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SAD is the tokenised surrogate produced by the vault and is freely retained because it is not the original value."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__100002",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best characterises a 'public' tier in a four-tier sensitivity scheme?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Disclosure causes no foreseeable harm; the data is approved for unrestricted external publication."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Disclosure outside the company would create competitive harm and requires legal review before any release."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Disclosure is restricted to staff and contractors who have signed the standard confidentiality undertaking."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Disclosure to anyone outside the originating team requires a documented business need and an access ticket."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__50934",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What new data category must automated classification systems now account for under 2025-2026 AI governance requirements?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "DNS query logs, classified as critical infrastructure telemetry"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Social media engagement metrics, classified as behavioral biometrics"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "AI training data sets, requiring distinct classification and lineage tracking"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Blockchain transaction hashes, classified as public financial records"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__871935",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A DSAR collector groups one subject's records by source tier. What does the script print?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "from collections import Counter\nRECORDS=[('kyc','restricted'),('billing','confidential'),\n         ('support','internal'),('crm','restricted')]\n\nc=Counter()\nfor _,tier in RECORDS:\n    c[tier]+=1\nprint(dict(c))",
    "label": "data-classification.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "{'restricted': 3, 'confidential': 1, 'internal': 0}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "{'restricted': 1, 'confidential': 2, 'internal': 1}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "{'restricted': 2, 'confidential': 1, 'internal': 1}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "{'internal': 1, 'confidential': 1, 'restricted': 2}"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__31152",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How should database schemas reflect data classification requirements for a multi-tier application?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Separate physical databases must be used for each classification level, regardless of operational cost"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Store classified data in separate tables or columns with appropriate encryption, auditing, and access controls matching the classification level"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Data classification is purely a documentation concern; database schemas need no special design for classified fields"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "All data should be stored in a single encrypted database regardless of classification: encryption equalizes sensitivity"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__105519",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing token-vault tokenisation versus format-preserving encryption (FPE) for protecting PAN while keeping downstream systems numeric, which point best supports tokenisation for PCI scope reduction?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Vault tokens are always longer than the original PAN by exactly four digits so they cannot fit existing schemas"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Vault tokens require analysts to memorise the original PAN before issuing the token to keep audit trail intact"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Vault tokens are forbidden by PCI DSS v4.0 in any system that processes recurring billing or refunds at scale"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Vault tokens have no mathematical link to the PAN; FPE keeps reversibility inside any system holding the key"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__926108",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A jq filter extracts S3 object tags from a Macie finding. What does the command print to stdout?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "echo '{\"resourcesAffected\":{\"s3Object\":{\"tags\":[\n  {\"key\":\"Classification\",\"value\":\"restricted\"},\n  {\"key\":\"Owner\",\"value\":\"fraud-team\"}]}}}' \\\n| jq -c '[.resourcesAffected.s3Object.tags[] | \"\\(.key)=\\(.value)\"]'",
    "label": "data-classification.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "[\"Classification=restricted\",\"Owner=fraud-team\"]"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "[{\"Key\":\"Classification\",\"Value\":\"restricted\"}]"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "{\"Classification\":\"restricted\",\"Owner\":\"fraud-team\"}"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Classification=restricted\\nOwner=fraud-team"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__17130",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A classification programme has been stable for two years. Which kind of event should auto-trigger a reclassification review on a specific dataset?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A team move that places the dataset's owner under a different reporting line in the engineering organisation chart"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A change to the storage cluster's underlying hardware refresh schedule by the platform team's operations group"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A new downstream use, a new sharing partner, or a regulator update changes the dataset's risk profile"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A renaming of the table column that holds the timestamp field used by the operational dashboard for time-series filtering"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__300007",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes how a DSAR (data subject access request) interacts with a classification scheme?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Tier labels exempt regulated stores from the response since regulator-mandated retention overrides the request."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Tier labels delay the response window by adding a documented legal-review step ahead of any data extraction."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Tier labels reduce the response surface to the marketing CRM only, since other tiers are out of scope for DSARs."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Tier labels guide the search across stores so personal-data sources are enumerated within the response window."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_classification__328419",
   "topic": "compliance",
   "subSkill": "data_classification",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A lineage walker propagates the maximum upstream tier to each downstream node. What does the script print for node 'report'?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "RANK={'public':0,'internal':1,'confidential':2,'restricted':3}\nINV={v:k for k,v in RANK.items()}\nNODES={'users':'restricted','orders':'confidential','catalog':'internal'}\nEDGES={'report':['users','orders'],'export':['report','catalog']}\n\ndef tier(n):\n    if n in NODES: return RANK[NODES[n]]\n    return max(tier(p) for p in EDGES[n])\nprint(INV[tier('report')])",
    "label": "data-classification.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "regulated"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "restricted"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "confidential"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "internal"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63730",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why should session IDs never appear in URLs?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "URLs have a maximum length that session IDs would exceed"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "URLs leak into browser history, server logs, and Referer headers"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Session IDs in URLs prevent HTTPS from encrypting the connection"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Session IDs in URLs are blocked by all modern browsers"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63523",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does the Secure cookie attribute guarantee?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The cookie is only sent over HTTPS connections"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The cookie is hidden from server-side code"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The cookie cannot be deleted by the user"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The cookie value is encrypted by the web browser"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63529",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is a key disadvantage of stateful (server-side) sessions compared to stateless sessions?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "They cannot support cookie-based session identifiers"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "They prevent the use of long-lived remember-me cookies"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "They expose all session data to client-side JavaScript code"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "They require a shared session store for horizontal scaling"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__50411",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why is magic-link authentication still in heavy production use at large consumer apps despite the broader push toward passkeys?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It is mandated by SOC 2 Type II controls for any product that handles customer data"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It is usable on any device with an email client and needs no prior credential enrollment"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It is the only authentication factor that the FIDO Alliance certifies for unattended workflows"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It is the cheapest method to integrate because email delivery has no per-message cost"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__201774433965",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your app is embedded inside a partner page in an iframe and its login cookie must still travel with those embedded requests in Chrome. Which attribute combination is required?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SameSite=Lax with Secure and a two year Max-Age value set"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "SameSite=Strict with Secure and a host only Domain value set"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SameSite=None with Secure and the Partitioned attribute set"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SameSite=Lax with Secure and the HttpOnly attribute also set"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__614809054510",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Browsers recognise two cookie name prefixes with different rules. Which constraints does the stricter of the two impose on a cookie the browser agrees to store?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "No Domain attribute at all, a Path of exactly /, and delivery over TLS"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A Domain attribute matching a registrable suffix, plus a Path of exactly /"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A Path equal to the request Path, plus an explicit Domain and Max-Age"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A Domain naming a parent site, a Path of /, and an expiry under a day"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__77982650674",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An embedded widget already sets its cookie with SameSite=None and Secure, yet browsers enforcing third-party restrictions still discard it. Which addition keeps the cookie usable in that embedded context?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Priority set to High, lifting the cookie above the eviction cutoff"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Partitioned, giving the cookie a separate jar per top-level site"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Max-Age raised beyond a day, exempting the cookie from the rules"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Domain set to the widget origin, rebinding the cookie to that host"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__63759",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A cookie is set with both "
      },
      {
       "t": "code",
       "v": "Max-Age=3600"
      },
      {
       "t": "text",
       "v": " and "
      },
      {
       "t": "code",
       "v": "Expires"
      },
      {
       "t": "text",
       "v": " pointing to yesterday. What does the browser do?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The cookie lives for 3600 seconds because Max-Age takes precedence over Expires"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The cookie never expires because the conflict disables both of these attributes"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The browser rejects the cookie outright due to conflicting directives"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The cookie is deleted immediately because Expires takes precedence"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__714507406989",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A cookie named __Host-sid is written with Path=/, Secure and Domain=example.com. How does a conforming browser treat that write?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Accepted, with the Domain attribute silently dropped by the browser"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Rejected outright, because the prefix forbids a Domain attribute"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Accepted, and then shared with every subdomain under that Domain"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Accepted, but downgraded to a host-only Domain scope on the write"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.session_management__19272",
   "topic": "auth_patterns",
   "subSkill": "session_management",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A session cookie is sent on cross-site POST requests and CSRF incidents appear. Which cookie control helps most?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Set Secure so the cookie is only transmitted over HTTPS in cross-site contexts"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Set a long Max-Age so a single cookie covers many cross-site interactions safely"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Set HttpOnly so cross-site scripts cannot read the cookie before the POST is issued"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Set SameSite=Lax or Strict so the cookie is withheld on cross-site POST requests"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63750",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is ABAC (Attribute-Based Access Control) best suited for?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Access decisions based on user, resource, and environment attributes"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Static role hierarchies where each role holds a fixed permission set"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Relationship graphs between users and the resources they share"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Static access control lists managed by system administrators"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63734",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A team defines an admin role whose permission set includes every member-role permission plus a handful of admin-only ones. They never re-list the member permissions inside the admin role definition. Which RBAC construct relies on this implicit propagation?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Dynamic role activation: the admin role's permissions are expanded only inside an active session and contract back to the base member set at session end"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Static separation of duty: the admin role's inherited permissions are constrained so the same user cannot also hold a conflicting senior approval role"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Hierarchical RBAC: the admin role inherits the member role's permissions through the role-to-role hierarchy without restating them"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Permission discovery: the engine derives the admin role's permission set at decision time from the member role's runtime permission set inferred from usage"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__310051",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Given this SpiceDB / Authzed CheckPermission call against a Zanzibar-shaped schema, what permissionship enum is printed?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "// @authzed/authzed-node 1, node 20\n// schema: definition document { relation reader: user; relation writer: user; permission view = reader + writer }\n// relationship: document:doc1#reader@user:alice\nconst res = await client.checkPermission({\n  resource: { objectType: 'document', objectId: 'doc1' },\n  permission: 'view',\n  subject: { object: { objectType: 'user', objectId: 'alice' } },\n});\nconsole.log(res.permissionship);",
    "label": "rbac.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "PERMISSIONSHIP_AWAITING_GRANT"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "PERMISSIONSHIP_HAS_PERMISSION"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "PERMISSIONSHIP_NONE_FOUND_AT"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "PERMISSIONSHIP_REQUIRES_LOOKUP"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__20522",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "In RBAC, why is it recommended to assign roles to user groups rather than individual users?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Updating a role's permissions reaches every member of the group at once"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Assigning roles to individuals requires a database join that is too slow at scale"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Individual role assignments bypass the least-privilege enforcement mechanism"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "RBAC specifications prohibit direct user-to-role assignments"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63834",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An app stores a flat "
      },
      {
       "t": "code",
       "v": "users.role"
      },
      {
       "t": "text",
       "v": " column with one value per user. A user invited to a second tenant overwrites their own role from 'admin' (their original tenant) to 'viewer' (the new tenant). What request-path bug does this produce in the original tenant?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The user's authority in the original tenant collapses to viewer because the single role column has no tenant scope and every check reads the same value everywhere"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The user retains admin in the original tenant because the directory keeps an internal version history of role values and authz checks read the most recent version per tenant id"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The user is automatically promoted to a platform-level admin across all tenants because the role-column update triggers a privilege escalation alarm that fails open by design"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The user is permanently locked out of both tenants because the directory schema rejects any user row whose role field has been written to more than once during its lifetime"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63723",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A compliance program adopts quarterly access reviews. During the review, managers are asked to re-attest each direct report's role assignments. Which RBAC discipline does this cadence operationalise?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Separation of duties: quarterly reviews detect toxic combinations between the assignments held by two different users in the same department"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Least privilege over time: assignments are recertified against current job function so dormant rights drift out of the user's role set"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Mediated access: quarterly reviews force every privileged action through an approval queue between the requester and the resource owner"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Defense in depth: review cadence overlaps with technical controls so the failure of any one mechanism still leaves the user adequately constrained"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__216865106357",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "After a platform migration, a build pipeline's service identity still carries the administrator binding it was given during cutover. The team wants a smaller blast radius without breaking nightly builds. What is the right first move?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Read the audit trail for the calls it truly made and scope a role to those"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Delete the binding now and put the admin grant back once a nightly build fails"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Give the pipeline a second identity and leave the current one in place"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Rotate the credential so a thief cannot make use of the elevated grant"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63836",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A developer adds a new 'reports:export' permission but forgets to add it to any role. Under a deny-by-default RBAC system, what happens when a user tries to export a report?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "No user can export reports because no role has been granted the permission"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Only admin users can export because admins bypass permission checks"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "All users can export because new permissions default to 'allow'"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The system throws an error because the permission was never mapped to any admin role"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__63583",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "In a multi-tenant SaaS application, how should roles be scoped?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Globally: one role per user across all tenants"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Per session: roles change with each new login"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Per API endpoint: each route defines its own role set"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Per organization: roles differ from tenant to tenant"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.rbac__310022",
   "topic": "auth_patterns",
   "subSkill": "rbac",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Given this OPA Rego policy and "
      },
      {
       "t": "code",
       "v": "opa eval"
      },
      {
       "t": "text",
       "v": " of data.authz.allow, what value is printed for the result?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "# opa 0.x, rego v1\npackage authz\nallow if {\n  input.role == \"admin\"\n  input.action == \"read\"\n}\n# query: data.authz.allow with input as {\"role\":\"admin\",\"action\":\"read\"}\n# result printed by `opa eval`",
    "label": "rbac.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "array of one"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "boolean true"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "object empty"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "string admin"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__63941",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which SSO best practice ensures that users are automatically deprovisioned when they leave the company?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Setting every session cookie to expire after 24 hours"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Requiring password rotation for all users every 90 days"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Automating provisioning and deprovisioning with SCIM"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Enabling MFA for every user account in the IdP"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__100011",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the core function of Single Sign-On in an enterprise application?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Replaces TLS certificates by signing API responses with a per-user RSA key issued at first login by the application"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Stores hashed passwords centrally so each application can verify them locally against a shared bcrypt-protected vault"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Encrypts every HTTP request between the browser and the application server using a symmetric key shared by all tenants"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Lets a user authenticate once with a central identity provider and use multiple applications without signing in again"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__730329300728",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A team weighs implementing SAML single logout against simply issuing short-lived app sessions with silent renewal. Which reasoning favours the short-lived option?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Short sessions hammer the identity provider token endpoint past its limits"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Silent renewal leans on third party cookies that identity provider domains set"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Server to server logout needs mutual TLS that few identity provider vendors will run"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Front channel propagation depends on browser reachability of every relying party"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__63940",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What key concepts must a Service Provider configure to integrate with a SAML 2.0 Identity Provider?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "OAuth client_id, client_secret, and redirect URI"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Entity ID, ACS URL, and the IdP's X.509 signing certificate"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "JWKS endpoint URL, the issuer claim, and the audience claim"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "API key, webhook callback URL, and rate limit tier"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__764924756419",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A security review finds that your SAML handler verifies the signature and the audience but never looks at the Conditions element's validity window. What is the concrete risk this creates?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Attribute values arrive base64 encoded and can no longer be decoded"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A captured message stays replayable for as long as the attacker keeps it"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The signature covers only the header, leaving the subject unprotected"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The provider will reject later logins until the clock skew has been fixed"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__63939",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does a break-glass account provide in enterprise SSO?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A temporary account created during security incidents for forensic analysis"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A read-only audit account that monitors SSO login patterns"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A shared team account used for after-hours on-call access"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "An emergency local administrator account for Identity Provider outages"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__19270",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is a key challenge of implementing global single logout across many apps?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Logout never affects refresh tokens issued by the identity provider"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "All applications share a single browser cookie by default in SSO"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "OIDC explicitly forbids logout notification callbacks between apps"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Distributed session invalidation may be eventual and failure-prone"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__50379",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "How does SCIM complement SSO in enterprise deployments?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SCIM encrypts SSO tokens during cross-domain transfers between identity providers"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "SCIM automates provisioning and deprovisioning so SSO access tracks HR events"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SCIM replaces SAML assertions with a more compact binary format for faster SSO"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SCIM provides real-time session synchronization between all SSO-connected applications"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__63753",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the risk of NOT implementing IdP failover testing in an SSO deployment?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The SP's ACS endpoint will stop accepting any HTTP requests"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "User sessions across all applications will be immediately terminated"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Users will receive outdated SAML assertions with expired certificates"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "If the IdP goes down, all connected applications become inaccessible with no fallback"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.sso__63704",
   "topic": "auth_patterns",
   "subSkill": "sso",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which protocol automates user provisioning and deprovisioning between an Identity Provider and multiple SaaS apps?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SAML (Security Assertion Markup Language)"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "XACML 3.0 (eXtensible Access Control Markup Language)"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "LDAP v3 (Lightweight Directory Access Protocol)"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SCIM (System for Cross-domain Identity Management)"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__63741",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A user enrolls in TOTP MFA and scans a QR code. What information does the QR code contain?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "otpauth://totp/Example:user@email.com\n  ?secret=JBSWY3DPEHPK3PXP\n  &issuer=Example\n  &algorithm=SHA1\n  &digits=6\n  &period=30",
    "label": "mfa.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A URL to download the authenticator app from the app store"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "An encrypted backup of the user's account credentials"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "An otpauth:// URI holding the secret, issuer, and period"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The server's public key for verifying TOTP codes"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__63813",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An app requires MFA for login but allows password-only access for the 'Change Email' endpoint. What is the security gap?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The Change Email endpoint is safe because it requires the current email for verification"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "MFA is only needed at login: subsequent actions inherit the authentication level"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "An attacker with a stolen password can change the account email and reset MFA"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Email changes on that endpoint are automatically reverted if MFA was not verified"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__50352",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why does NIST SP 800-63-4 shift from checklist-based requirements to a Digital Identity Risk Management (DIRM) framework?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It makes organizations continuously evaluate threats and select assurance levels per context"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It mandates quarterly third-party audits to verify compliance with static requirements"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It delegates all authentication decisions to end users rather than organizations"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It eliminates assurance levels entirely in favor of a single universal authentication standard"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__63561",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What are the three categories of authentication factors?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Your username, your password, your email address"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Something you know, something you have, something you are"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Your IP address, your browser fingerprint, and your cookie"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A public key, a private key, and a signed certificate"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__19244",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why is SMS OTP generally considered weaker than phishing-resistant passkeys?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "SMS codes are typed by the user, while passkey responses are not"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "SMS codes use shorter character sets than passkey signatures"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "SMS is exposed to SIM-swap and interception risks"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "SMS arrives over an unencrypted channel that lacks TLS protection"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__210025",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What value of credential.response.constructor.name is logged after a successful WebAuthn navigator.credentials.create call?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "// W3C WebAuthn L3, browser ctx\nconst cred = await navigator.credentials.create({ publicKey: {\n  challenge: new Uint8Array(32),\n  rp: { name: 'Acme', id: 'acme.test' },\n  user: { id: new Uint8Array(16), name: 'a@b', displayName: 'A' },\n  pubKeyCredParams: [{ type: 'public-key', alg: -7 }],\n}});\nconsole.log(cred.response.constructor.name);",
    "label": "mfa.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "AuthenticatorAssertionResponse"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "AuthenticatorRegistrationResponse"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "AuthenticatorAttestationResponse"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "PublicKeyCredentialResponse"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__19294",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Attackers trigger endless push prompts until users approve one. Which mitigation works best?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Number matching or challenge binding to defeat MFA fatigue"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Reduce the prompt timeout so unanswered prompts expire faster"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Rate-limit push notification frequency per authentication session"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Send push notifications only during business hours as a deterrent"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__200334",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does the inherence factor in authentication rely on?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Something the user controls physically, such as a security key plug-in"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Something the user accesses transiently, such as an emailed code link"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Something the user recalls from memory, such as a passphrase or pin"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Something inherent to the user, such as a fingerprint or face scan"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__143674421764",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An account with app-based one-time codes enrolled was taken over. The logs show the intruder never submitted a code; they answered knowledge questions on the self-service reset page and set a new password. What does this incident show?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A live session cookie was replayed off a stolen browser profile before any challenge"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The one-time code algorithm was broken and future values predicted"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The generator seed was cloned from the enrolled device and reused elsewhere"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Recovery offers a parallel route to full access at a lower assurance level"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.mfa__637288810267",
   "topic": "auth_patterns",
   "subSkill": "mfa",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A verifier accepts a valid TOTP value and keeps no record of it. The same digits are submitted again 8 seconds later. What does RFC 6238 require of the verifier?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Both submissions pass because the code has not expired"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The second submission is refused for that same time step"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Only a resync of the client clock can block the reuse here"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Acceptance holds until the shared counter increments again"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__200205",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes a Linux kernel capability in the context of dropping privileges?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It is a sandbox profile that proxies syscalls through a userspace agent and rewrites their arguments inline."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It is one slice of root power that can be granted or removed from a process independently of the others."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It is a per-binary signature that the loader checks before mapping the executable into memory at startup."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It is a namespace that isolates a process tree from the host's view of users, processes, and mount points."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__200201",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes a capability-based authorization model?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An unforgeable token represents the right to perform a specific action on a specific object and is passed by reference."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A directory of group memberships represents the rights a user has and is consulted for every protected action call."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A static configuration list represents allowed IP ranges and is enforced before any user-level checks run on a path."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A shared signing key represents trust between services and is used to mint generic permissions on demand at runtime."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__301937",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing 'a wildcard egress NetworkPolicy from app pods' with 'an allow-list NetworkPolicy naming each external destination', which best states the allow-list's least-privilege benefit if the app is later compromised?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Outbound traffic to attacker-controlled hosts is logged at the pod boundary so exfiltration channels alert"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Outbound traffic to attacker-controlled hosts is rewritten at the pod boundary so exfiltration ends in honeypots"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Outbound traffic to attacker-controlled hosts is dropped at the pod boundary so exfiltration channels close"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Outbound traffic to attacker-controlled hosts is rate-limited so exfiltration takes longer than the alert window"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__267843",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is logged when this Node script runs as a non-root user on Linux?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "const fs = require('fs');\nfs.writeFileSync('/tmp/x', '');\ntry {\n  fs.chownSync('/tmp/x', 0, 0);\n} catch (e) {\n  console.log(e.code);\n}",
    "label": "least-privilege.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "EINVAL"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "EPERM"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "EACCES"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "EROFS"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__65304",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does RFC 9700 (January 2025) specify about OAuth 2.0 access token lifetimes?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Access tokens must be encrypted with the resource server's public key before transmission"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Access tokens must include the user's full profile claims to reduce authorization server load"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Access tokens must be short-lived and context-bound to minimize the impact of token theft or replay"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Access tokens must expire within exactly 60 seconds regardless of the grant type"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__20016",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A microservice needs to write to one specific S3 bucket. The service is deployed with an IAM role that has 's3:' permissions on ''. What is the least-privilege alternative?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An S3 bucket policy that allows all actions from the service's IP address"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "An IAM role with only 's3:PutObject' and 's3:GetObject' on the specific bucket ARN"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "An IAM role with 's3:*' restricted to a specific region"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "An IAM role with all S3 permissions but with an explicit Deny for bucket deletion"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__301936",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing a CI job that uses a long-lived deploy key in repository secrets with one that federates via OIDC to assume a deployment role, which best captures the OIDC pattern's least-privilege advantage?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Cloud trust is scoped to the build artefact hash so a leaked secret cannot apply to a different binary upload"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Cloud trust is scoped to the workflow and branch claim so a leaked secret cannot be replayed by any other repo"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Cloud trust is scoped to the workflow and branch claim so a leaked secret cannot be read from any other shell"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Cloud trust is scoped to a single executor minute so a leaked secret cannot survive past the runner reboot"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__65467",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is RFC 9700's key recommendation for OAuth 2.0 access tokens?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Access tokens must be short-lived and context-bound to prevent replay attacks"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Access tokens must include the user's full profile data to avoid additional API calls"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Access tokens must be generated using quantum-resistant algorithms by 2027"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Access tokens must be encrypted with AES-256 and stored in HttpOnly cookies only"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__945627",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A Linux process has only CAP_NET_BIND_SERVICE. What does the program print when it tries to bind on TCP port 80?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "# binary granted ONLY: CAP_NET_BIND_SERVICE+ep\n# C pseudo-main:\n#   s = socket(AF_INET, SOCK_STREAM);\n#   if (bind(s, 0.0.0.0:80) == 0)\n#       puts(\"bound on :80\");\n#   else\n#       perror(\"bind\");\nsetcap cap_net_bind_service+ep ./srv\n./srv",
    "label": "least-privilege.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "EPERM on bind"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "bound on :80"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "EACCES on bind"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "fatal: errno"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.least_privilege__65298",
   "topic": "secure_coding",
   "subSkill": "least_privilege",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What happens when Node.js is started with the "
      },
      {
       "t": "code",
       "v": "--permission"
      },
      {
       "t": "text",
       "v": " flag but no "
      },
      {
       "t": "code",
       "v": "--allow-*"
      },
      {
       "t": "text",
       "v": " flags?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Only filesystem access is restricted; network and child processes remain open"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Everything is denied by default: filesystem, network, child processes, and workers are all blocked until explicitly allowed"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Node.js starts in an interactive mode prompting the user to configure each permission"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Node.js runs normally but logs a warning about missing permission flags"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__50400",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Reviewing API-key handling, an auditor distinguishes 'storage' from 'transport.' What is the correct primitive for each?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A one-way hash for storage, mutual TLS for transport: clients must present an X.509 cert"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Symmetric encryption for storage, TLS for transport: decrypt to compare on each call"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A one-way hash for storage, TLS for transport, never re-display the stored value"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Symmetric encryption for storage, an HMAC envelope for transport: signed body protects the key"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__196385302928",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Several providers reissued their credentials in a format with a fixed identifiable prefix and a trailing checksum. What does that shape primarily buy them?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The token gets shorter, cutting bandwidth on every authenticated request a client makes"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Clients verify the checksum offline and skip the round trip to the issuer entirely"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Automated scanners match leaked strings with high precision, enabling fast provider side revocation"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The checksum widens the key space, leaving the token resistant to brute force guessing at any realistic scale"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__200613",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does a secret manager do in API-key handling?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A central store that signs each outbound payload using a per-tenant HMAC line"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A central store that injects credentials at runtime so source repos stay clean"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A central store that scans pull requests and rejects any commit touching env files"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A central store that proxies every API call so the credential never leaves it ever"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__659329283330",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A team stores machine API credentials hashed with bcrypt at cost 12 and repeats that hashing on every incoming request. Which failure does this design produce as traffic grows?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Bcrypt truncates past 72 bytes, so distinct credentials open one account"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Verification burns CPU on each call and becomes a self inflicted denial of service"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The cost factor is frozen at write time, so old records verify under weaker work forever"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The per record salt forces a table scan, so lookups slow as the key count grows"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__19309",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A key was leaked to logs, but nothing ever alerted on it. Which control closes that gap?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Mandate TLS on every leg so the key in the leaked log is unreadable to outside observers"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Pin every key to a single source IP so the credential is unusable from any other network"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Treat the incident as low-severity and rotate the key on the next scheduled rotation pass"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Anomaly detection over per-key usage with secret-scanning feeds for public-source leaks"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__19268",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing 'store the API key hashed' with 'store the API key encrypted with a KMS-managed key,' what does the hashed approach concede in exchange for stronger compromise resilience?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The key cannot be validated without a network round trip to the hosted KMS service"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The key cannot be issued by an automated rotation API on the issuer side"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The key cannot be used in any flow that requires a constant-time comparison"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The key cannot be re-displayed to the customer after the initial creation moment"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__310043",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Given the snippet that revokes a key by setting revokedAt and then queries without a revocation filter, what status does console.log print?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "// node 20, prisma 5\nawait prisma.apiKey.update({ where: { id }, data: { revokedAt: new Date() } });\nconst row = await prisma.apiKey.findFirst({ where: { keyHash: h } });\nconst words = row ? ['still', 'authorized'] : ['revoked', 'rejected'];\nconsole.log(words.join(' '));",
    "label": "api-keys.ts"
   },
   "widget": {
    "kind": "predict_output",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "revoked rejected"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "expired rejected"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "not_found result"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "still authorized"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__200677",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why do mature platforms expose a 'last used at' timestamp per credential?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It allows the gateway to throttle credentials whose latency has drifted upward lately"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It feeds an autoscaler hint that prewarms isolates near the credential's last region"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It surfaces dormant credentials as candidates for safe revocation during cleanups"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It anchors the per-call HMAC so the receiver can detect out-of-order request streams"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__19310",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Clients send API keys in URL query strings for convenience. Why is this problematic?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Query strings cannot exceed the URL length limit imposed by intermediate proxies and routers"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Query strings travel outside the TLS-encrypted portion of the HTTPS request envelope"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Query parameters trigger preflight CORS rejections that block authenticated cross-origin calls"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Query parameters propagate into access logs, CDN logs, browser history, and Referer headers"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "auth_patterns.api_keys__200374",
   "topic": "auth_patterns",
   "subSkill": "api_keys",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "In a payment-style credential pair, what is the publishable key?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A non-secret identifier safe to ship inside browser bundles"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A short-lived token returned after a customer's checkout session"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A signing key used by the host to verify replay-protected requests"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A secret intended for server-to-server billing webhooks only"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__53857",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What OIDC-based mechanism allows CI systems to generate provenance without long-lived secrets?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The CI system uses a long-lived OAuth client credential to authenticate against a hosted signing API"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The CI system generates a self-signed certificate and uploads it to a central trust store"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The CI system encrypts the provenance data with the registry's public key and uploads the resulting ciphertext"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The CI system's OIDC identity token is exchanged for a short-lived Sigstore signing certificate from Fulcio"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__77411",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "You want to use GitHub Actions OIDC to authenticate "
      },
      {
       "t": "code",
       "v": "npm publish"
      },
      {
       "t": "text",
       "v": " to a private registry without storing npm tokens as GitHub Secrets. Which OIDC claims should the private registry validate?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The "
       },
       {
        "t": "code",
        "v": "jti"
       },
       {
        "t": "text",
        "v": " (JWT ID) claim to prevent token replay attacks"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The "
       },
       {
        "t": "code",
        "v": "repository"
       },
       {
        "t": "text",
        "v": ", "
       },
       {
        "t": "code",
        "v": "repository_owner"
       },
       {
        "t": "text",
        "v": ", "
       },
       {
        "t": "code",
        "v": "ref"
       },
       {
        "t": "text",
        "v": ", and "
       },
       {
        "t": "code",
        "v": "workflow"
       },
       {
        "t": "text",
        "v": " claims to ensure the publish came from an authorized repository, owner, branch, and workflow"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Only the "
       },
       {
        "t": "code",
        "v": "iss"
       },
       {
        "t": "text",
        "v": " (issuer) claim to verify it came from GitHub, since all GitHub repos are trusted"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The "
       },
       {
        "t": "code",
        "v": "actor"
       },
       {
        "t": "text",
        "v": " and "
       },
       {
        "t": "code",
        "v": "actor_id"
       },
       {
        "t": "text",
        "v": " claims to verify which developer triggered the workflow"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__326905",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Verification of an image with "
      },
      {
       "t": "code",
       "v": "cosign verify --certificate-identity-regexp ... --certificate-oidc-issuer ..."
      },
      {
       "t": "text",
       "v": " fails with "
      },
      {
       "t": "code",
       "v": "transparency log entry not found"
      },
      {
       "t": "text",
       "v": ". The image was signed 6 months ago with "
      },
      {
       "t": "code",
       "v": "--tlog-upload=false"
      },
      {
       "t": "text",
       "v": ". What probably broke it?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Public good Fulcio root rotated and the old cert chain is now untrusted"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Cosign default policy now rejects SHA-1 entries from older Rekor shards"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Registry GC pruned the "
       },
       {
        "t": "code",
        "v": ".sig"
       },
       {
        "t": "text",
        "v": " tag tied to the original signing event"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Signing certificate expired and no Rekor entry was uploaded for it"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__400789",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Comparing keyless signing via Fulcio with sigstore's optional bring-your-own-key flow, what does the keyless model trade away?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The ability to verify without trusting a public certificate authority"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Support for verifying images entirely offline with cached registry data"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Compatibility with the in-toto attestation envelope used by SLSA tools"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The capacity to publish signatures alongside images in OCI registries"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__54148",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What does a PyPI Publish Attestation (v1) allow consumers to verify?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "That a specific release distribution was uploaded via a Trusted Publisher, and exactly which identity did it"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "That the package's setup.py and pyproject.toml were validated against PyPI's static-analysis ruleset before upload"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "That the project's repository has branch protection enabled on the branch where the build was triggered from"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "That every transitive Python dependency was rebuilt from source inside the Trusted Publisher's workflow environment"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__53936",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What provenance information can you verify by running "
      },
      {
       "t": "code",
       "v": "npm audit signatures"
      },
      {
       "t": "text",
       "v": " on a project?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Whether each installed package has a valid registry signature or Sigstore provenance attestation"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Whether each package's source code matches a known-good hash in a government database"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Whether each package maintainer has enabled two-factor authentication"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Whether each package's license is compatible with your project's license"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__200706",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the "
      },
      {
       "t": "code",
       "v": "byproducts"
      },
      {
       "t": "text",
       "v": " field's role inside SLSA Provenance v1 "
      },
      {
       "t": "code",
       "v": "runDetails"
      },
      {
       "t": "text",
       "v": "?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Lists discarded test reports redacted from the public attestation envelope body"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Captures additional build outputs that aren't the primary subject artifacts"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Records intermediate cache hits to enable downstream build acceleration runs"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Contains a digest tree of every transient file written into the build sandbox"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__200505",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes what "
      },
      {
       "t": "code",
       "v": "cosign attest"
      },
      {
       "t": "text",
       "v": " produces?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An updated image manifest where labels record build parameters as plain text"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A Rekor transparency-log entry containing the raw artifact bytes themselves"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A detached PGP signature file uploaded to a separate keyserver for lookup"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A signed in-toto attestation stored alongside the OCI artifact in its registry"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__53933",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What role does Rekor play in npm provenance verification?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It mirrors every npm package tarball so integrity can be compared byte-for-byte during verification"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It stores the private keys used to sign npm packages inside a tamper-resistant hardware security module"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It acts as a certificate revocation list that tracks compromised npm publisher signing certificates"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It serves as an immutable transparency log that records every provenance attestation for public auditability"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.provenance__54149",
   "topic": "supply_chain_security",
   "subSkill": "provenance",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Why does extending software supply chain provenance (like SLSA) to AI model artifacts represent a meaningful security advancement?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Model weights can be tampered with post-training to introduce backdoors or biases. Provenance attestations cryptographically bind a published model to its training pipeline and source, enabling consumers to verify the model wasn't modified after training"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Model provenance is required by law in all jurisdictions under emerging AI regulation frameworks"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Provenance prevents adversarial examples from being effective against models signed with Sigstore"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "AI models are stored as binary files that cannot be scanned by traditional vulnerability scanners, so provenance is the only security control available"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__700204",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Your S3 lifecycle rule deletes objects under prefix /uploads/ after 365 days. Reports show 'objects deleted: 0' for the last 30 days. Bucket inventory confirms thousands of objects older than a year. What is the cause?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Intelligent-Tiering moved the objects to a deep archive class which lifecycle rules cannot directly delete from"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Object versioning is enabled and the lifecycle rule lacks a non-current-version expiration clause"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Object Lock is set to governance mode and the lifecycle rule needs an explicit bypass-retention flag"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Bucket replication to a paired region recreates objects faster than the lifecycle rule can expire them"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__400534",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Designing retention for a third-party processor (Stripe, Intercom, Slack) vs your own database - what's the right way to think about your obligations as controller?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Third-party processor data is out-of-scope from your retention schedule because the processor holds it; your obligation begins only after data returns to your environment via export"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The processor is jointly liable under Article 28 so retention scheduling is owned by them; your ROPA records the processor's published retention without needing your own duration"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Processors are bound by their own SOC 2 reports: quoting the processor's SOC 2 retention controls in your schedule is the standard auditor-accepted shortcut for evidencing duration"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "You remain responsible: the DPA must require the processor to erase/return data on instruction, and your retention schedule must include the processor as a row with its own clock"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__400564",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the correct characterization of the interaction between sub-processor data and the controller's retention schedule under GDPR Article 28?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The processor agreement must bind the sub-processor to the controller's retention and erasure instructions for the data."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The processor agreement must require the sub-processor to delete data immediately on each lawful basis change at the controller."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The processor agreement must compel the sub-processor to publish its retention schedule in a publicly accessible policy page."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The processor agreement must allow the sub-processor to set retention independently provided it is no longer than the controller's."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__50961",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What data retention challenge does the EU AI Act create for AI model providers when combined with GDPR's storage limitation principle?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "AI model providers must delete all training data immediately after model training completes"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "AI training data must be documented and traceable for compliance but cannot be retained indefinitely due to GDPR storage limitation"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The EU AI Act exempts all AI training data from GDPR retention limits permanently"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "GDPR storage limitation only applies to structured databases, not to AI training datasets"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__17135",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A litigation hold notice arrives covering a subset of customer records. Which adjustment to the running retention pipeline is required?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Continue deletion on schedule and rely on the most recent backup to restore evidence if litigation requires it"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Re-route the affected records into an immutable WORM bucket and continue normal deletion on the active dataset"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Per-record suspension of automated deletion for in-scope items with a hold-reason and release-trigger captured"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Increase the retention window for the entire affected data category by the duration of the expected litigation"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__50959",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What significant change did the FTC's June 2025 COPPA amendments introduce for data retention of children's information?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Set a fixed maximum retention window for all children's data measured from the account-creation date regardless of purpose"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Allow reuse of retained children's data for product analytics and model training under the original collection consent"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Permit indefinite retention of children's data so long as it stays encrypted and access is restricted to platform staff"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Retain children's data only as long as needed for the disclosed purpose, barring reuse to improve products or train models beyond it"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__100253",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What's the difference between 'soft delete' and 'hard delete' in the context of a GDPR right-to-erasure request?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Soft delete preserves referential integrity by leaving foreign keys intact; hard delete cascades to all child records but requires a separate legal sign-off"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Soft delete is reversible within a 30-day window; hard delete is irreversible and must therefore be approved by the DPO before the deletion job runs"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Soft delete sets a deleted_at flag but the row is still present; hard delete removes the row so it cannot satisfy an Article 17 erasure on its own"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Soft delete archives the row to a cold table for analytics; hard delete is the only state where the regulator considers the data fully out of the controller's possession"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__200334",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A team debates whether to drive deletion via a 'scheduled job' or via 'TTL on the row itself' (e.g. DynamoDB TTL, Postgres expiry column + cron). What's the audit-relevant difference?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A scheduled job produces a discrete run log (start, count, errors) auditors can sample; TTL-based deletion is asynchronous with no per-row deletion evidence trail"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "A scheduled job runs at fixed intervals so latency is bounded; TTL deletion runs continuously with strict per-record SLAs the database engine enforces and exposes"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A scheduled job lets you batch and log per-record outcomes; TTL deletion is preferred because the storage engine retains a tombstone for the full retention window"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A scheduled job is preferred for low-volume tables only; TTL is the recommended audit-approved pattern when the table exceeds about one million active rows"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__17156",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A company runs 40 services, each deleting personal data with its own team-written script and no central policy translation. Honouring a single right-to-be-forgotten request means chasing every team's script output by hand. What is the substantive failure mode for the controller?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Team-by-team scripts force the controller to negotiate sub-processor agreements with each internal service team"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Team-by-team scripts conflict with GDPR's joint-controller rules unless every team independently registers as a controller"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Inconsistent enforcement produces gaps in coverage and prevents the controller from evidencing erasure across the estate"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Team-by-team scripts trigger article 30 ROPA filings to be split into per-service registers across the organisation"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.data_retention__17187",
   "topic": "compliance",
   "subSkill": "data_retention",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Different regions apply one global retention period despite local law differences. What should change?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Use the shortest acceptable period to minimize data exposure risk"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Apply the longest required retention period globally to ensure compliance"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Jurisdiction-specific retention rules keyed to each subject's applicable law"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Let each team determine retention periods based on their storage budget"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__400004",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the GDPR Article 30 Record of Processing Activities (RoPA)?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A regulatory filing the controller submits to the supervisory authority before any new processing activity is launched."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "An audit report the controller commissions annually to demonstrate compliance to enterprise customers during procurement reviews."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "An external publication the controller posts so that data subjects can review processing details before they submit any personal data."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "An internal inventory the controller maintains describing purposes, categories of data, recipients, transfers, retention, and security measures."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__200003",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the GDPR principle of storage limitation?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Personal data is replicated to a disaster-recovery region with a documented recovery point objective."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Personal data is kept in identifiable form no longer than is necessary for the purposes of processing."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Personal data is held in encrypted form whenever it sits at rest in any application data store."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Personal data is duplicated only where a documented business need justifies an additional copy."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__301454",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A dev implements DSAR export as a button that runs an ad-hoc SELECT * across 12 services and emails a zip to the user. Six months later support reports a wrong-user data leak. What's the privacy-by-design root cause?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Identity binding wasn't verified before export: the request lacked step-up authentication"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Identity binding wasn't escrowed after export: the request lacked a custodial release-key handshake"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Identity binding wasn't notarised before export: the request lacked an eIDAS-level assurance chain"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Identity binding wasn't audited after export: the request lacked a deferred third-party signature"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__31183",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is differential privacy and in what scenarios can it be applied to share data analytics without exposing individual records?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Differential privacy encrypts individual records before aggregating statistics, which are then decrypted for analysis"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Differential privacy adds calibrated mathematical noise to query results, providing provable guarantees that any individual's data has minimal impact on the output"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Differential privacy replaces personal data with synthetic records generated by a separate privacy engine"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Differential privacy is a theoretical concept with no production implementations outside academic research"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__400521",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An LLM feature lets users paste internal documents to summarise. Metrics show 4% of pastes contain identifiers matching customer email patterns. Legal asks for a privacy-by-design fix before the next release. Which mitigation addresses the proactive-not-reactive principle most directly?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Strip detected identifiers client-side before the payload leaves the browser and warn the user inline"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Strip detected identifiers server-side after ingestion and emit a redaction event to the audit pipeline"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Strip detected identifiers from training corpora via a nightly batch redaction job over the LLM cache"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Strip detected identifiers from model prompts via a server middleware that mutates the prompt template"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__50970",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Under GDPR Art. 25(1), at which lifecycle moment is the controller required to embed data-protection measures?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "At the time of supervisory authority registration before any personal data is collected at all"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "At the time of breach notification when investigating affected data subjects' residual exposure"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "At the time of determining the means of processing and at the time of processing itself"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "At the time of internal audit completion following each annual SOC 2 Type 2 attestation cycle"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__17139",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A signup flow exposes marketing analytics, location sharing, and partner data export - each as separate toggles. Under Art. 25(2), what is the required initial state of these toggles?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "On for the toggles tied to product improvement; off for those tied to partner monetisation"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Off by default; each requires a specific affirmative act before the corresponding processing begins"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Off by default; users can re-enable them later via a granular profile-settings surface"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "On by default; users can opt out via a single 'reject non-essential' link in the footer"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__17142",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A platform team debates where to aggregate analytics events. Which placement most directly reduces the controller's GDPR risk surface?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Aggregate at the application layer's response handler before each event is emitted upstream"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Aggregate inside the warehouse via materialised views consumed by all analyst notebooks"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Aggregate at the BI tool's semantic layer so dashboards reference grouped rather than raw rows"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Aggregate and drop direct identifiers at the ingest pipeline, before any downstream store retains the raw row"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__17189",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An app ships with every data-sharing toggle already switched on, and the user must go find them to turn them off. Why is this risky?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Justified when the broader data sharing measurably improves the user experience"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The most privacy-protective state is not the default, so users bear the burden of opting out"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Acceptable practice as long as the privacy policy clearly explains the data sharing"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Low risk because users can tighten the settings themselves after onboarding"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "compliance.privacy_by_design__300009",
   "topic": "compliance",
   "subSkill": "privacy_by_design",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the role of a Data Protection Officer (DPO) under GDPR Articles 37-39?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "An executive function that approves engineering change requests touching personal data prior to production deployment."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "An internal audit function that signs off the annual record of processing activities as a controller representative."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "An independent function that monitors compliance, advises on obligations, and acts as a contact point for supervisory authorities."
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "An external counsel function that negotiates standard contractual clauses with each new sub-processor relationship."
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__527014",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Given the chained hash audit entries, what property holds for "
      },
      {
       "t": "code",
       "v": "entry2.prevHash"
      },
      {
       "t": "text",
       "v": " relative to "
      },
      {
       "t": "code",
       "v": "entry1"
      },
      {
       "t": "text",
       "v": "?"
      }
     ]
    }
   ],
   "code": {
    "lang": "ts",
    "code": "import { createHash } from 'node:crypto';\nconst h = (o) => createHash('sha256').update(JSON.stringify(o)).digest('hex');\nconst entry1 = { i: 1, ev: 'login', prevHash: '0'.repeat(64) };\nconst entry2 = { i: 2, ev: 'logout', prevHash: h(entry1) };\nconsole.log(entry2.prevHash === h(entry1));",
    "label": "logging-security.ts"
   },
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "equals sha256(JSON.stringify(entry1))"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "equals hmac(entry1, secretkey)"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "equals sha256(entry1.payload only)"
       }
      ],
      "shape": "code"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "equals sha256(entry1.prevHash)"
       }
      ],
      "shape": "code"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__10216",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Across a fan-out pipeline (app → Fluent Bit → S3 + Splunk + warehouse), at what point should sensitive values be scrubbed from log output to minimize accidental leakage?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Manual review of every sampled entry before it leaves the application host"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Vendor-side data-loss-prevention rules applied during dashboard rendering only"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Raw emission from services with cleanup queries run nightly in the warehouse"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Structured logging with field-level redaction before sink ingestion"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__65080",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is tamper-evident logging, and what technique makes it possible?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Logs signed with the application's TLS certificate before storage"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Append-only logs with cryptographic chaining, where each entry includes a hash of the previous entry"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Logs encrypted with a public key that only the security team can decrypt"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Logs stored on a read-only filesystem with daily rotation"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__65155",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which type of security event should always be logged?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Failed logins, since successes are routine noise"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Successful logins, since failures are rarely useful"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Both successful and failed authentication attempts"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Logins from IP addresses outside the office range"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__650284",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 4,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the canonical residual risk of relying on regex-only redaction at the log emitter?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Patterns drift behind the data, so novel field shapes or nested structures slip past unredacted"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The library cannot serialize matched groups into JSON so structured downstream parsers reject the line"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The CPU cost of running the matcher per line dominates throughput on busy emitters in steady state"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The matcher requires a network call to a central rule service which becomes a single point of failure"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__65335",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the purpose of correlation IDs across microservices from a security perspective?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "They authenticate requests between services by embedding the caller's identity in the ID"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "They prevent replay attacks by ensuring each request ID is used only once across all services"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "They enable tracing a single attack chain across multiple services, showing how a compromised request propagated through the system"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "They encrypt inter-service communication by deriving per-request encryption keys"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__65079",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the purpose of correlation IDs in a microservices architecture?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "They trace a single request across multiple services, enabling end-to-end debugging and attack chain analysis"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "They deduplicate identical log entries that are emitted across several different services"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "They rate-limit how much each service may log in order to prevent log flooding during traffic spikes"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "They encrypt each log entry in transit so it can be transmitted securely between the services"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__65075",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which of the following should NEVER appear in application logs?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "HTTP status codes and response times"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "User agent strings and IP addresses"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Timestamps and request IDs"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Passwords, API keys, and session tokens"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__637402",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 1,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes the structured-logging approach compared to building messages with string concatenation?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It records named fields as discrete key/value pairs so values are not pasted into a free-text template"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It produces shorter log lines by inlining all variables directly into the printable text"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It moves user-supplied strings into the message template at write-time for easier grep usage"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It pastes user input into the log template earlier so the log shipper can parse the line later"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "secure_coding.logging_security__65495",
   "topic": "secure_coding",
   "subSkill": "logging_security",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What role does a SIEM system play in the security alerting chain that OWASP A09:2025 demands?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It encrypts and compresses log files for long-term compliance storage"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It aggregates, correlates, and analyzes security events from multiple sources to detect attack patterns and trigger automated alerts"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It provides real-time visualization dashboards for executive security reporting"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It generates synthetic security events to test incident response readiness"
       }
      ],
      "shape": "short"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__300457",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes how the public-good Sigstore root of trust is distributed to clients?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Via DNS TXT records served from the sigstore.dev zone and refreshed every 24-hour interval"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Via a hardcoded constant in each cosign release that ships with the signing CA fingerprint"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Via a TUF repository signed by ceremony-rooted offline keys held by maintainers"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Via the host operating system trust store managed by the platform package manager updates"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77275",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 5,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A sophisticated attacker has compromised your Fulcio instance (not Rekor) and can issue certificates with arbitrary identities. Which defense-in-depth mechanism limits the blast radius?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "TUF's threshold signing requirement on the Fulcio root key prevents a single instance compromise from affecting the downstream certificate issuance for signers in the org"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Cosign's built-in anomaly detection model flags signing certificates that do not match the expected statistical pattern for the configured organizational identity on the account"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Certificate Transparency-style monitoring of Fulcio's issuance log: any certificate issued for your identity that doesn't correspond to a legitimate build is detectable within the monitor's polling interval"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Rekor's append-only transparency log rejects a signature whose certificate chain traces back to a compromised Fulcio instance: the check happens at verification time rather than at signing, so a bad certificate is caught downstream"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77571",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the purpose of the "
      },
      {
       "t": "code",
       "v": "--certificate-identity-regexp"
      },
      {
       "t": "text",
       "v": " flag in cosign verify?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "It matches the Rekor inclusion-proof entry's metadata fields against the supplied regex pattern as part of the transparency log verification step inside cosign verify"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "It validates the X.509 leaf certificate's Common Name (CN) field against the supplied regex pattern at verification time before accepting the signature as valid"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "It uses a regular expression to match the SAN (Subject Alternative Name) in the signing certificate, allowing flexible identity matching patterns like "
       },
       {
        "t": "code",
        "v": "https://github.com/myorg/.*"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "It checks the signer's long-term public key fingerprint against the regex pattern supplied by the verifying policy at the moment the verifier loads the artifact"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__54112",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What major change does Cosign v3's bundle format migration require for verification workflows?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "All Sigstore bundles must now be uploaded to a single centralized Sigstore cloud registry before downstream consumers are able to verify any image's signature offline"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Bundle files must additionally be signed by a second, independent signing service distinct from the Sigstore deployment used to create the original artifact signature"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The --bundle flag specifying an output file for the Sigstore bundle is now required instead of optional"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Verification now requires both a PGP public key and a Sigstore bundle to be supplied simultaneously, and cosign rejects any verification attempt missing either input"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__54061",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "An organization deploys a private Sigstore instance with its own Fulcio CA and Rekor log. What security assumption changes compared to using the public Sigstore infrastructure?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The private Rekor transparency log loses its append-only property in self-hosted deployments, letting the organization delete entries on demand"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Private Fulcio instances are forced to issue signing certificates valid for 24 hours instead of 10 minutes, widening the post-issuance attack window"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The organization's Fulcio CA becomes a single point of trust: a compromise of the private CA allows forging signing certificates for any identity"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Private Sigstore instances cannot use OIDC for keyless signing and must fall back to long-lived key-based workflows for every release"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77665",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "cosign supports signing with keys stored in cloud KMS services. Which KMS providers are supported?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Only AWS KMS and Google Cloud KMS are first-class; Azure Key Vault and HashiCorp Vault each require building a separate out-of-tree cosign plugin maintained outside the sigstore organization"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Any KMS that exposes the PKCS#11 standard interface, accessed by cosign through a generic pkcs11:// URI that delegates token discovery and PIN entry to the local p11-kit configuration"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Cloud KMS integration is gated behind a paid cosign Enterprise edition; the open-source cosign binary only supports local cosign.key files and Fulcio-issued keyless certificates"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "AWS KMS, Google Cloud KMS, Azure Key Vault, and HashiCorp Vault - cosign abstracts the KMS interaction behind a URI scheme (e.g., awskms://, gcpkms://, azurekms://, hashivault://)"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__77616",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "You sign a container image with cosign using a KMS key (not keyless). The verification command requires the public key. Where should this public key be published?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "In a well-known, tamper-evident location: the project's repository (signed commit), documentation, or a TUF-managed trust root, allowing verifiers to discover and trust the key"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Embedded in the OCI registry alongside the signed image as a registry-side annotation that verifiers fetch from the manifest at verification time"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "Inside the Rekor transparency log, which functions as the canonical public key directory mapping each signer's identity to their current verification key"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "Nowhere; cosign automatically discovers the public key by querying the KMS ARN referenced in the signature's metadata during verification of the artifact"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__53879",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "What is the purpose of cosign's 'attest' command compared to its 'sign' command?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "The attest command batches signatures across many artifacts in a single invocation, while sign processes one artifact reference at a time"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "The attest command attaches structured metadata (like SBOM or SLSA provenance) to an artifact, while sign simply creates a signature over the artifact digest"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The attest command uses traditional key-based signing under the hood, while sign always exercises the keyless workflow against Fulcio"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The attest command verifies someone else's existing signature on an artifact, while sign creates a brand new signature over its digest"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__200346",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 2,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "Which statement best describes what cosign attest writes to the registry?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "A signed in-toto envelope referencing the image as the attestation subject"
       }
      ],
      "shape": "short"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "An additional tag containing the encrypted base image filesystem layers for replay"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "A registry-side webhook that triggers verification on any subsequent client image pull"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "A plain JSON manifest pinning the build commit SHA and Dockerfile path information"
       }
      ],
      "shape": "long"
     }
    ]
   }
  },
  {
   "questionId": "supply_chain_security.artifact_signing__54012",
   "topic": "supply_chain_security",
   "subSkill": "artifact_signing",
   "difficulty": 3,
   "stem": [
    {
     "type": "p",
     "runs": [
      {
       "t": "text",
       "v": "A team configures Kyverno to enforce cosign signature verification on all pod images. Why might pods using 'gcr.io/distroless/static:nonroot' still bypass this verification?"
      }
     ]
    }
   ],
   "widget": {
    "kind": "mcq",
    "options": [
     {
      "id": "o1",
      "label": [
       {
        "t": "text",
        "v": "Kyverno cannot read images without a shell, since its cosign integration shells into the running container to enumerate the attached signatures from inside"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o2",
      "label": [
       {
        "t": "text",
        "v": "Distroless images are explicitly exempted from OCI signature verification by the Kubernetes admission API, so any compliant policy controller skips them automatically"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o3",
      "label": [
       {
        "t": "text",
        "v": "The image is pulled through a registry mirror that does not replicate the cosign signature artifact, so Kyverno cannot fetch the signature and the policy's failurePolicy decides the outcome"
       }
      ],
      "shape": "long"
     },
     {
      "id": "o4",
      "label": [
       {
        "t": "text",
        "v": "The 'nonroot' tag is a reserved Kubernetes tag that Kyverno's mutating webhook strips from the pod spec before the validating phase ever evaluates the policy"
       }
      ],
      "shape": "long"
     }
    ]
   }
  }
 ]
}
