🔐

Security Engineering & Operations Topics

Operational security practices, secure systems implementation, threat modeling, penetration testing, vulnerability assessment, and security operations at production scale. Covers network security, endpoint security, secure architecture implementation, incident response mechanics, and security automation. Distinct from Security & Compliance (which addresses governance, compliance frameworks, and policy) and from Security Research & Innovation (which addresses novel techniques and research contributions).

Forensic Artifact Analysis and Timeline Reconstruction

Extracting meaning from acquired forensic data. Covers file system forensics, memory forensics and volatile-data analysis, forensic artifact identification and interpretation, deleted-file and unallocated-space recovery, log-based forensic investigation, and timeline construction and event reconstruction. The analytical core of turning raw images into a defensible account of what happened.

86 questions

Security Fundamentals and Core Concepts

The foundational vocabulary and principles of information security: the CIA triad (confidentiality, integrity, availability) and related properties (authenticity, non-repudiation), defense in depth, least privilege, and the distinction between threats, vulnerabilities, and risk. Establishes the mental model every practitioner reasons from before diving into any specialized domain. Concept-level fundamentals, not tool usage or governance frameworks.

0 questions

Secure Software Delivery: DevSecOps, Pipeline, and Supply Chain Security

Embedding security into how software is built, assembled from dependencies, and shipped. Covers shift-left and secure-SDLC practices, infrastructure-as-code security, CI/CD pipeline and secrets management, integrating security scanning into build and deploy, and configuration and secret management across environments, together with software supply chain security: software composition analysis (SCA), dependency and open-source vulnerability management, build-provenance and artifact integrity, and mitigating supply-chain attack vectors. The 'secure the delivery pipeline and everything it pulls in' discipline, distinct from vendor-risk governance.

0 questions

Security Automation, Tooling, and Operations at Scale

Engineering and operating security capabilities at scale. Covers security automation and scripting (e.g. Python for security), building and engineering internal security tools, security-stack integration and tool consolidation, security tool evaluation and selection, security metrics and observability, and running enterprise security operations reliably at scale. The 'make security repeatable, measurable, and operable' engineering layer.

0 questions

Network Security and Defense

Securing networks at the infrastructure layer. Covers firewalls, ACLs and rule design, network device hardening and secure configuration, intrusion detection and prevention systems, VPN and remote-access encryption, network protocols and their security properties, and packet-level traffic analysis. The hands-on network-defense layer, distinct from zero-trust architecture strategy.

0 questions

Reverse Engineering and Malware Analysis

Analyzing malicious code and unknown binaries. Covers static and dynamic malware analysis, behavioral analysis and indicator extraction, reverse engineering of binaries and firmware, and code obfuscation and deobfuscation. The deep-technical capability to understand what a piece of hostile or unknown code actually does.

22 questions

Exploitation, Post-Exploitation, and Red Team Operations

The hands-on offensive tradecraft of compromising, pivoting through, and persisting in systems while evading defenses. Covers exploit development, privilege escalation, Active Directory and Windows exploitation, lateral movement, persistence, command-and-control, and attack chaining, extending into adversary-emulation campaigns: red-team engagement planning and objectives, multi-stage attack planning, operational security for offensive operators, and detection and defense evasion including web application firewall detection and bypass. The advanced offensive-operations layer executed against real targets, where staying undetected is itself an objective, distinct from the methodical scoped-assessment workflow of a penetration test.

8 questions

Digital Evidence Law, Admissibility, and Expert Testimony

The legal framework surrounding digital evidence. Covers evidence admissibility standards and legal requirements, jurisdictional and regulatory requirements for digital evidence, the legal and ethical considerations of forensic work, and presenting findings as an expert witness including testimony and cross-examination. The law-and-courtroom slice of forensics absorbed from the retired legal-compliance-hr category, scoped to the Digital Forensic Examiner role.

60 questions

Incident Response and Containment

Managing security incidents from detection through recovery. Covers incident response process and playbooks, containment and remediation, data-breach investigation methodology, data-exfiltration detection and analysis, root-cause and post-incident analysis, and fraud and complex-attack investigation. The operational 'a compromise is happening, now what' discipline, distinct from broader production-outage incident management.

39 questions
Page 1/2