KNOWLEDGE / 09
Security and DevSecOps
Threat modelling, security testing, and integrating security practices into delivery.
Questions and practice
Open a question to see the answer, examples, and exercises.
How does authentication differ from authorization?Junior
Answer
Authentication establishes who performs an action; authorization decides whether that identity may act on a resource.
Examples
- A valid user may sign in but still lack permission to read another user’s order.
Practice exercises
- Negatively test access to another user’s order in a local training environment.
How do confidentiality, integrity, and availability support security-risk analysis?Junior
Answer
The CIA triad provides three basic impact categories: data disclosure, unauthorised modification, and unavailability. Risk also considers likelihood, exposure, and asset value. One vulnerability may affect several properties, so severity should not be derived from the technical finding type alone.
Examples
- An IDOR exposes another user’s data, while the ability to change it also violates integrity.
Practice exercises
- Choose three product assets and describe confidentiality, integrity, and availability threats for each.
Why does XSS prevention require contextual output encoding instead of one filter?Junior
Answer
Dangerous characters have different meanings in HTML, attribute, URL, CSS, and JavaScript contexts. Encode data for its specific output context, avoid unsafe sinks, and sanitise allowed HTML with a proven library. Input validation helps but cannot stop every XSS vector by itself.
Examples
- A string safe in an HTML text node may be dangerous inside a JavaScript string or href.
Practice exercises
- Mark the source, transformation, and sink for three user inputs and choose protection for each context.
Why do SAST and DAST complement each other?Middle
Answer
SAST analyses code without running it; DAST tests a running system’s behaviour. Both have gaps and false positives.
Examples
- SAST may see an unsafe data flow, while DAST finds a misconfiguration visible only at runtime.
Practice exercises
- For one service, identify findings expected from SAST, DAST, and manual review.
What should be tested in an authentication session beyond successful login?Middle
Answer
Test session-ID rotation after login and privilege changes, expiry, logout invalidation, concurrent sessions, brute-force protection, reset flows, and secure cookie attributes. Defects often live in state transitions rather than the login form. Sensitive actions may require re-authentication.
Examples
- A stolen pre-login session ID must not remain valid after the user authenticates.
Practice exercises
- Build a state model for login, MFA, refresh, logout, and password reset, then identify invalid transitions.
What do SCA and an SBOM provide in a software supply chain?Middle
Answer
SCA finds known risks in dependencies, while an SBOM inventories components and versions for traceability. A finding needs triage: is the component reachable, exploitable, deployed, and protected by compensating controls? No known CVE does not prove safety, and an automatic upgrade can also create regressions.
Examples
- A critical CVE in a build-only package may carry different risk from a reachable library on the production request path.
Practice exercises
- For one dependency finding, record version, path, reachability, exploitability, fix, owner, and deadline.
What is a trust boundary?Senior
Answer
A boundary between zones with different trust levels through which data or control passes.
Examples
- Moving from a public API to an internal queue requires validation, authorization, and auditing.
Practice exercises
- Build a STRIDE model for a test server and mark every trust boundary.
How does threat modelling turn into concrete checks?Senior
Answer
The team describes assets, actors, data flows, trust boundaries, and possible abuse. STRIDE or attack trees help cover threat classes but do not replace domain analysis. Every meaningful threat receives a mitigation, verification method, owner, and residual-risk decision.
Examples
- At a public API → internal service boundary, a spoofing threat leads to tests of token validation, audience, and service identity.
Practice exercises
- Create a data-flow diagram for a small service and turn five threats into concrete security tests.
Which controls reduce a container’s blast radius?Senior
Answer
Run containers as non-root with minimal Linux capabilities, a read-only filesystem, resource limits, seccomp or AppArmor policy, and restricted networking. Use minimal, traceable, scanned images, but remember that container isolation is not equivalent to a VM boundary. Runtime monitoring complements preventive controls.
Examples
- A service needs no shell and writes only to a dedicated temporary volume while its root filesystem remains read-only.
Practice exercises
- Review a deployment manifest for privilege escalation, capabilities, secrets, network policy, and resource limits.