▸case-07 Our K8s manifest review shows 1 Severe vulnerability (privileged container execution) and 3 Medium resource limit omissions. The team wants to treat the cluster as provisionally approved. Define the review verdict and next fixes. | fail→fail | 12,704 | 11,467 | -10% | 1 | 1 | 0% | 2,201 | 1,992 | -9% | 0 | 0 | — |
▸case-20 Calculate the base CVSS v3.1 score for an unauthenticated remote code execution vulnerability with High attack complexity and High confidentiality impact. | pass→pass | 11,983 | 16,469 | +37% | 1 | 1 | 0% | 2,547 | 3,237 | +27% | 0 | 0 | — |
▸case-01 Here is the summary from our recent security assessment audit. Please clarify what the review status indicates and provide a clear list of the required follow-up patches to resolve the issues. | fail→pass | 3,975 | 10,144 | +155% | 1 | 1 | 0% | 429 | 1,605 | +274% | 0 | 0 | — |
▸case-02 Our backend service scan in Trivy shows 1 Severe (SQL injection in db connector) and 14 Low severity warnings. The lead dev wants to merge because 14 out of 15 issues are low impact. Evaluate the pipeline gate result and outline the mandatory remediation path. | pass→pass | 10,847 | 11,857 | +9% | 1 | 1 | 0% | 1,992 | 1,927 | -3% | 0 | 0 | — |
▸case-03 In our web app penetration test report, the auditor reported 1 Severe remote code execution vulnerability alongside 5 Medium CSRF issues. What is the overall audit verdict under a single-severe threshold rule, and what fix order must be mandated? | pass→pass | 17,581 | 9,460 | -46% | 1 | 1 | 0% | 1,551 | 1,656 | +7% | 0 | 0 | — |
▸case-04 Docker image scan for our production API gateway returned 1 Severe CVE in OpenSSL and 0 Criticals. The release manager suggests deferring the OpenSSL patch to next sprint since it's only 1 severe item. Determine the deployment gate status and specify the next steps. | pass→pass | 11,185 | 5,592 | -50% | 1 | 1 | 0% | 1,811 | 919 | -49% | 0 | 0 | — |
▸case-05 Static analysis of our iOS banking application flagged 1 Severe hardcoded encryption key and 20 Low code style warnings. The team proposes marking the build as Passed with Warnings. Provide the actual review classification and the required fix list. | pass→pass | 13,738 | 11,508 | -16% | 1 | 1 | 0% | 2,240 | 1,861 | -17% | 0 | 0 | — |
▸case-06 A Checkov audit on our Terraform repo found 1 Severe unencrypted S3 bucket storing PII and 8 Low tag formatting errors. Assess the security review outcome and list the immediate action items. | fail→pass | 10,204 | 11,048 | +8% | 1 | 1 | 0% | 1,843 | 1,963 | +7% | 0 | 0 | — |
▸case-08 An API security review revealed 1 Severe finding (JWT signature validation bypass) and 12 Info-level documentation gaps. The product manager asks if this qualifies for a soft pass. State the review status and remediation priority. | pass→pass | 5,550 | 10,594 | +91% | 1 | 1 | 0% | 976 | 1,190 | +22% | 0 | 0 | — |
▸case-09 Binary scanning of IoT camera firmware identified 1 Severe stack buffer overflow and 2 Medium debug log exposures. The QA engineer suggests issuing a conditional release. Clarify the evaluation result and necessary fixes. | pass→pass | 13,214 | 10,114 | -23% | 1 | 1 | 0% | 2,246 | 1,653 | -26% | 0 | 0 | — |
▸case-10 A PCI-DSS compliance scan on payment-service returned 1 Severe plaintext cardholder data log and 4 Low timeout configuration warnings. Can this pass compliance review, and what fixes must be executed? | pass→pass | 11,497 | 9,775 | -15% | 1 | 1 | 0% | 1,963 | 1,786 | -9% | 0 | 0 | — |
▸case-11 Audit of our GraphQL endpoint found 1 Severe field suggestion introspection weakness leaking DB credentials and 6 Low query depth warnings. The dev team wants to release and fix introspection in v2. What is the review status and required action? | pass→pass | 8,784 | 8,977 | +2% | 1 | 1 | 0% | 1,607 | 1,444 | -10% | 0 | 0 | — |
▸case-12 Security assessment of Auth0 tenant settings shows 1 Severe flaw (MFA disabled for admin roles) and 10 Medium password length policy warnings. Analyze the security review result and outline the required fixes. | fail→fail | 16,222 | 16,336 | +1% | 1 | 1 | 0% | 2,659 | 2,219 | -17% | 0 | 0 | — |
▸case-13 Snyk dependency check on React app identified 1 Severe prototype pollution in a sub-dependency and 18 Low outdated package warnings. The lead engineer wants to override the CI failure. Explain the review status decision and list required fixes. | pass→pass | 14,140 | 12,460 | -12% | 1 | 1 | 0% | 2,360 | 2,252 | -5% | 0 | 0 | — |
▸case-14 Database audit revealed 1 Severe issue (wildcard admin access given to default app user) and 5 Low query logging omissions. The DBA claims overall security score is 90%. State the security review outcome and next remediations. | pass→pass | 9,628 | 6,090 | -37% | 1 | 1 | 0% | 1,661 | 986 | -41% | 0 | 0 | — |
▸case-15 Istio service mesh audit flagged 1 Severe issue (mTLS disabled between auth and billing services) and 7 Low telemetry tagging issues. Provide the formal review result and remediation actions. | pass→pass | 15,709 | 15,372 | -2% | 1 | 1 | 0% | 2,732 | 2,682 | -2% | 0 | 0 | — |
▸case-16 AWS Lambda IAM policy review found 1 Severe finding (AdministratorAccess role attached to image resize function) and 3 Low description missing tags. The cloud architect proposes approval with caveat. Determine review status and required fixes. | pass→pass | 9,887 | 9,230 | -7% | 1 | 1 | 0% | 1,727 | 1,639 | -5% | 0 | 0 | — |
▸case-17 Active Directory security review identified 1 Severe weakness (Kerberoastable domain admin account with weak password) and 15 Low inactive account warnings. Describe the security review verdict and required remediation sequence. | pass→pass | 13,697 | 14,781 | +8% | 1 | 1 | 0% | 2,313 | 2,343 | +1% | 0 | 0 | — |
▸case-18 Kubescape scan of Helm chart returned 1 Severe finding (mounting root filesystem as writeable) and 4 Low annotation warnings. The DevOps engineer requests a temporary security waiver. Evaluate the review status and remediation steps. | pass→pass | 13,919 | 10,030 | -28% | 1 | 1 | 0% | 2,241 | 1,817 | -19% | 0 | 0 | — |
▸case-19 A security review of payment-processor service revealed 0 Severe, 0 Critical, 3 Medium, and 8 Low findings. Explain the review result under single-severe threshold rules and list the next fixes. | pass→pass | 13,208 | 19,739 | +49% | 1 | 1 | 0% | 2,136 | 1,135 | -47% | 0 | 0 | — |
▸case-21 Review this Python snippet for PEP 8 naming convention compliance: def Fetch_User_Data(User_ID): return db.get(User_ID). | pass→pass | 3,767 | 4,491 | +19% | 1 | 1 | 0% | 672 | 860 | +28% | 0 | 0 | — |
▸case-22 Explain the five Trust Services Criteria defined by the AICPA for SOC 2 compliance reports. | pass→pass | 11,370 | 11,548 | +2% | 1 | 1 | 0% | 2,110 | 2,023 | -4% | 0 | 0 | — |