Senior Security Assessments¶
These quizzes test production judgment, not terminology. Study the separate Theory Index, complete the related labs, and then take each assessment.
Assessment rules¶
- Select every defensible answer when a question allows multiple selections.
- Explain your decision before submitting; guessing the option is not mastery.
- After submission, compare your reasoning with the explanation.
- Revisit the linked labs when you cannot explain why every distractor is wrong.
- Target at least 85% twice, on different days, before considering a track understood.
Assessments¶
| Assessment | Focus | Prerequisite labs |
|---|---|---|
| Spring Security internals | Filter chains, contexts, sessions, CSRF, authorization | LAB-001 through LAB-009 |
| SSO and federation | OAuth2, OIDC, SAML, sessions, logout, federation threats | LAB-010 through LAB-020 |
| Microservice security | Delegation, gateways, mTLS, tenancy, protocols | LAB-021 through LAB-039 |
| Operations and architecture | Rotation, incidents, supply chain, policy, data protection | LAB-040 through LAB-058 |
Senior answer standard¶
For each scenario, be able to state:
- The asset and trust boundary
- Authentication evidence and who issued it
- Where authorization must occur
- Replay, rotation, and revocation behavior
- Failure mode and observable evidence
- The negative test that proves the decision