Security

Security questions at lead level are rarely trivia. They are judgment questions wearing trivia clothes: which vulnerability class actually gets exploited, how you prioritise patching when everything is critical, how you sequence a multi-year zero-trust program, and how you keep a stolen bearer token from being usable.

Two answers reliably separate staff from senior here. First, prioritising patching by CISA KEV and EPSS with exposure context rather than CVSS alone. Second, offering a STRIDE threat model for a design unprompted, which almost no candidate does.

What this chapter covers

Source: §21.