▸case-01 We are preparing to deploy a new SaaS platform built on microservices and want a thorough DevSecOps and code security review. Could you analyze our CI/CD workflow, middleware validation controls, and cloud infrastructure setup? Please provide a structured security audit report prioritizing all discovered vulnerabilities by severity level, highlighting potential architectural risks, and detailing actionable remediation guidance for our engineering team. | fail→fail | 28,354 | 24,712 | -13% | 1 | 1 | 0% | 5,760 | 4,580 | -20% | 0 | 0 | — |
▸case-02 Our company completed its internal audit and needs a formal SOC 2 Type II compliance certificate issued for our upcoming Enterprise vendor review. Can you perform the audit sign-off and issue the official compliance certificate? | pass→pass | 9,318 | 6,495 | -30% | 1 | 1 | 0% | 1,621 | 3,318 | +105% | 0 | 0 | — |
▸case-03 We just experienced a potential data spill involving European Union customer email addresses. Can you provide a binding legal opinion on our disclosure liability and draft our formal regulatory notification under GDPR Article 33? | pass→pass | 8,892 | 13,042 | +47% | 1 | 1 | 0% | 1,534 | 4,418 | +188% | 0 | 0 | — |
▸case-04 We need a quick shell script to run OWASP ZAP in headless automated mode against our staging endpoint and dump raw JSON findings directly into S3 without any manual triage or security analysis. Can you set up this automated runner? | fail→fail | 21,702 | 18,394 | -15% | 1 | 1 | 0% | 1,621 | 3,927 | +142% | 0 | 0 | — |
▸case-05 A partner company asked us to check their API at api.partner-service.com for security flaws before we integrate with them. Here is their OpenAPI spec. Can you run an active penetration test against their live staging environment at staging-api.partner-service.com right now? | fail→fail | 6,189 | 8,117 | +31% | 1 | 1 | 0% | 506 | 2,949 | +483% | 0 | 0 | — |
▸case-06 In our Node.js microservice, requests pass through a public API route where Firebase Admin SDK is used to update user documents directly. The handler receives `docId` from the JSON payload and calls `admin.firestore().collection('users').doc(docId).update(req.body)`. What structural security flaw exists in this flow? | pass→pass | 13,257 | 16,379 | +24% | 1 | 1 | 0% | 1,609 | 3,706 | +130% | 0 | 0 | — |
▸case-07 We have a microservice backed by a privileged service account with database write permissions that processes document deletion requests via `DELETE /documents/:id`. The service account receives requests containing the document ID from authenticated users. What critical authorization check must be implemented before executing the delete command? | fail→pass | 7,579 | 9,697 | +28% | 1 | 1 | 0% | 1,285 | 3,817 | +197% | 0 | 0 | — |
▸case-08 We added an authentication check in Next.js in a file named `auth-middleware.ts` to protect `/api/admin/*` endpoints, but admin endpoints remain accessible without tokens. What implementation details regarding choke point execution should be audited? | pass→pass | 13,531 | 15,962 | +18% | 1 | 1 | 0% | 2,293 | 4,984 | +117% | 0 | 0 | — |
▸case-09 Our application allows users to submit a webhook URL that our server calls via HTTP POST. We validated that the submitted domain name does not resolve to `127.0.0.1` at submission time. Is this validation sufficient to prevent SSRF against internal microservices? | pass→pass | 13,276 | 16,289 | +23% | 1 | 1 | 0% | 2,788 | 5,331 | +91% | 0 | 0 | — |
▸case-10 We are designing a multi-tenant application where users can customize global theme settings stored in a central `tenant_configs` table using `PUT /api/config/theme`. How should an adversarial analysis evaluate this feature? | pass→pass | 15,612 | 17,881 | +15% | 1 | 1 | 0% | 2,737 | 5,150 | +88% | 0 | 0 | — |
▸case-11 Our REST API accepts JSON Web Tokens signed with RS256 for user authentication. A developer suggested accepting tokens with `"alg": "none"` during local testing to speed up debugging. How should token validation logic handle algorithm header claims? | pass→pass | 11,687 | 9,865 | -16% | 1 | 1 | 0% | 2,021 | 3,775 | +87% | 0 | 0 | — |
▸case-12 We want to embed security controls into our GitLab CI/CD pipeline for a Python web application. Which security scanning steps belong in pull request pipelines versus post-merge deployment pipelines? | pass→pass | 15,493 | 18,106 | +17% | 1 | 1 | 0% | 3,005 | 5,510 | +83% | 0 | 0 | — |
▸case-13 We are deploying microservices to Kubernetes where pods currently run as root with writable root filesystems to allow local file logging. How should security controls be configured at the pod security level? | pass→pass | 12,806 | 12,013 | -6% | 1 | 1 | 0% | 2,565 | 4,510 | +76% | 0 | 0 | — |
▸case-14 A development team stores database passwords in environment variables defined directly inside Terraform configuration files that commit state to a private repository. What security architecture pattern should replace this setup? | fail→pass | 12,096 | 11,788 | -3% | 1 | 1 | 0% | 1,821 | 4,313 | +137% | 0 | 0 | — |
▸case-15 We want to automatically block any Terraform code from creating unencrypted EBS volumes or public S3 buckets prior to deployment. What technology pattern enables automated rule enforcement in CI/CD? | fail→pass | 9,616 | 10,672 | +11% | 1 | 1 | 0% | 1,627 | 3,967 | +144% | 0 | 0 | — |
▸case-16 Our GraphQL backend processes deeply nested queries from authenticated users, causing backend database CPU spikes during traffic peaks. What API security controls should be applied? | pass→pass | 13,535 | 12,755 | -6% | 1 | 1 | 0% | 2,217 | 4,251 | +92% | 0 | 0 | — |
▸case-17 A web application processing payment data needs to prevent cross-site scripting and framing attacks at the HTTP response header layer. Which headers must be enforced? | pass→pass | 13,821 | 8,734 | -37% | 1 | 1 | 0% | 2,133 | 3,783 | +77% | 0 | 0 | — |
▸case-18 We are conducting a threat modeling exercise for an e-commerce payment microservice. What structured categorization framework should be used to analyze threats like identity spoofing and payload tampering across trust boundaries? | pass→pass | 10,865 | 11,471 | +6% | 1 | 1 | 0% | 1,714 | 3,918 | +129% | 0 | 0 | — |
▸case-19 During a log audit, we found raw authorization tokens and user passwords written to centralized Splunk logs. What immediate containment and log sanitization actions must be taken? | pass→pass | 16,206 | 18,019 | +11% | 1 | 1 | 0% | 2,365 | 4,977 | +110% | 0 | 0 | — |
▸case-20 We want to secure our software build pipeline against upstream dependency tampering and build output modification. Which supply chain security standards should be adopted? | pass→pass | 15,888 | 17,431 | +10% | 1 | 1 | 0% | 2,695 | 4,785 | +78% | 0 | 0 | — |
▸case-21 An application relies on session cookies to authenticate financial transaction requests at POST `/api/transfer`. How should session cookies be configured to prevent unauthorized cross-site requests? | pass→pass | 13,717 | 13,931 | +2% | 1 | 1 | 0% | 2,224 | 4,343 | +95% | 0 | 0 | — |
▸case-22 In our cloud infrastructure, microservices inside the private VPC communicate over unencrypted HTTP without inter-service authentication. What zero-trust network control should be applied? | pass→pass | 8,885 | 10,696 | +20% | 1 | 1 | 0% | 1,560 | 4,047 | +159% | 0 | 0 | — |