Start here Read
Knowledge Self-Assessment Matrix
Rate each topic: 0 = never seen · 1 = aware · 2 = can explain · 3 = can teach/apply under pressure
12 min read
17 sections
Update the Status column as you study. Use the Notes column for specific gaps.
How to Use
- Go through each row and honestly rate yourself 0–3.
- Highlight rows where score < 2 — these are your priority study areas.
- Re-assess every 1–2 weeks.
- Before an interview: all rows should be ≥ 2. Rows critical for the role should be 3.
Networking & Protocols
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| OSI Model (all 7 layers, what lives where) | |||
| TCP three-way handshake + state machine | |||
| TCP vs UDP — when/why each | |||
| TLS handshake (1.2 vs 1.3 differences) | |||
| DNS resolution chain (recursive, authoritative) | |||
| DNS record types (A, AAAA, MX, NS, PTR, CNAME, SOA) | |||
| DNS exfiltration detection | |||
| ARP + ARP spoofing | |||
| DHCP flow (DORA) | |||
| BGP basics + hijacking | |||
| HTTP/S request-response headers | |||
| HTTP status codes (1xx-5xx) | |||
| ICMP + traceroute mechanics | |||
| VPN vs Tor vs Proxy | |||
| SSL/TLS attacks: POODLE, BEAST, HEARTBLEED | |||
| PKI + certificate chains + trust stores | |||
| CAM table overflow | |||
| tcpdump + Wireshark usage |
Web Application Security
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| Same-Origin Policy + CORS | |||
| XSS — reflected, stored, DOM-based | |||
| CSRF — mechanism + mitigations | |||
| SQL injection — blind, union, time-based | |||
| SSRF — exploitation + mitigations | |||
| Directory traversal | |||
| HSTS + HPKP | |||
| Cookie flags (HttpOnly, Secure, SameSite) | |||
| OAuth 2.0 flow + bearer token abuse | |||
| JWT — structure, none-alg attack, signing | |||
| Local/remote file inclusion | |||
| Insecure deserialization | |||
| OWASP Web Top 10 (all 10) | |||
| Content Security Policy (CSP) | |||
| Burp Suite usage |
Cryptography
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| Encryption vs Encoding vs Hashing vs Signing | |||
| Symmetric encryption: AES-GCM | |||
| Asymmetric encryption: RSA, ECC | |||
| Diffie-Hellman key exchange | |||
| Forward secrecy (ephemeral keys) | |||
| HMAC — construction and use cases | |||
| Hash functions: MD5, SHA-1, SHA-256, BLAKE3 | |||
| Block vs stream ciphers | |||
| Padding oracle attacks | |||
| Timing attacks + constant-time comparison | |||
| Entropy + PRNG | |||
| PKI — CA hierarchy, cert revocation (CRL, OCSP) | |||
| Envelope encryption |
Authentication & Identity
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| Password hashing: bcrypt, Argon2, scrypt | |||
| MFA methods — TOTP, FIDO2, SMS | |||
| OAuth 2.0 + OIDC flow | |||
| SAML 2.0 | |||
| Kerberos — ticket lifecycle, golden/silver ticket | |||
| Pass-the-hash + Pass-the-ticket | |||
| Service accounts vs user accounts | |||
| Federated identity | |||
| JWT attacks (alg:none, weak secret) | |||
| Session management + fixation |
Linux & Operating Systems
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| Linux kernel architecture (ring 0 vs ring 3) | |||
| SUID/SGID binary abuse | |||
| Sudo misconfigurations + GTFOBins | |||
| DirtyCOW (CVE-2016-5195) | |||
| DirtyPipe (CVE-2022-0847) | |||
| PwnKit / Polkit (CVE-2021-4034) | |||
| eBPF verifier bugs (CVE-2021-3490) | |||
| Looney Tunables (CVE-2023-4911) | |||
| OverlayFS privesc (CVE-2023-0386) | |||
| Cron job abuse | |||
| NFS no_root_squash | |||
| Kernel mitigations: ASLR, SMEP, SMAP, stack canary | |||
| Capabilities (CAP_SYS_ADMIN, CAP_NET_ADMIN, etc.) | |||
| Namespaces (pid, net, user, mnt) | |||
| /proc, /tmp, /shadow — attacker relevance | |||
| linpeas / linux-exploit-suggester | |||
| Active Directory: Kerberos, BloodHound, DCSync | |||
| Windows: SMB, NTLM, Pass-the-hash |
macOS Security
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| SIP — what it protects, known bypasses | |||
| TCC — architecture, tccd, database schema | |||
| TCC service types (FDA, Screen Recording, etc.) | |||
| TCC bypass via entitlement-privileged process | |||
| App Sandbox + data containers (~/Library/Containers) | |||
| com.apple.macl xattr — drag-and-drop grant, irrevocable | |||
| Archive Utility — privileges, preference-driven behavior | |||
| CVE-2026-28910 — full 3-weakness chain + app hijacking | |||
| AUHelperService XPC design flaw (FDA entitlement, no caller check) | |||
| Gatekeeper + quarantine xattr + notarisation | |||
| FileVault 2 — AES-XTS-256, Secure Enclave | |||
| Secure Boot levels (Full / Reduced / No Security) | |||
| XProtect + MRT + XProtect Remediator | |||
| AMFI — code signing enforcement in kernel | |||
| macOS persistence: LaunchAgents, LaunchDaemons, login items | |||
| macOS pf firewall rules | |||
| Application Firewall + stealth mode | |||
| codesign — verify app bundle integrity | |||
| macOS BSM audit framework | |||
| T2 / Secure Enclave — what it protects |
CI/CD & Supply Chain Security
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| CICD-SEC-1: Insufficient flow controls | |||
| CICD-SEC-2: IAM in pipelines | |||
| CICD-SEC-3: Dependency chain abuse | |||
| CICD-SEC-4: Poisoned Pipeline Execution (PPE) | |||
| CICD-SEC-5: Pipeline-Based Access Controls (PBAC) | |||
| CICD-SEC-6: Credential hygiene | |||
| CICD-SEC-7: Insecure system config | |||
| CICD-SEC-8: 3rd party services | |||
| CICD-SEC-9: Artifact integrity (Sigstore/SLSA) | |||
| CICD-SEC-10: Logging + visibility | |||
GitHub Actions: pull_request vs pull_request_target | |||
| OIDC in CI (replacing long-lived credentials) | |||
| Dependency confusion attack | |||
| Typosquatting | |||
| SLSA levels 1–4 | |||
| Sigstore / cosign | |||
| Secrets scanning (truffleHog, gitleaks) | |||
| Branch protection + CODEOWNERS |
Kubernetes
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| Control plane components (API server, etcd, scheduler) | |||
| Pod lifecycle + workload types | |||
| Service types (ClusterIP, NodePort, LoadBalancer) | |||
| RBAC — Role vs ClusterRole vs Binding | |||
| Dangerous RBAC permissions | |||
| Pod Security Standards (privileged/baseline/restricted) | |||
| Network Policies — default deny + allow patterns | |||
| Admission controllers (OPA, Kyverno) | |||
| Secrets management (native vs Vault vs ESO) | |||
| etcd encryption at rest | |||
| Container escape techniques (privileged, docker.sock, CAP_SYS_ADMIN) | |||
| Falco runtime security | |||
| Workload Identity (GKE) | |||
| Binary Authorization | |||
| K8s audit logging setup | |||
| IR: quarantine pod via NetworkPolicy | |||
| IR: SA token compromise response |
AWS Security
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| IAM policy evaluation order | |||
| IAM privilege escalation paths | |||
| SCPs + permission boundaries | |||
| Security Groups vs NACLs | |||
| VPC Flow Logs | |||
| IMDSv1 vs IMDSv2 (SSRF mitigation) | |||
| CloudTrail — setup, data events, log validation | |||
| GuardDuty — key findings, integration | |||
| Security Hub | |||
| AWS Config + conformance packs | |||
| KMS — CMK, envelope encryption, key policy | |||
| S3 security (block public access, bucket policy) | |||
| Secrets Manager vs SSM Parameter Store | |||
| Inspector (EC2 + ECR scanning) | |||
| Macie (data classification) | |||
| IAM Access Analyzer | |||
| Lambda security (execution role, resource policy) | |||
| IR: compromised IAM key (contain + investigate) | |||
| IR: EC2 isolation + snapshot |
GCP Security
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| GCP resource hierarchy (Org → Folder → Project) | |||
| IAM principals (user, SA, allUsers, allAuthenticatedUsers) | |||
| Role types (primitive vs predefined vs custom) | |||
| Dangerous GCP IAM permissions | |||
| Org Policy constraints | |||
| VPC Service Controls (perimeters, access levels) | |||
| Security Command Center (SCC) feature set | |||
| Cloud Audit Logs (3 types) | |||
| Workload Identity for GKE | |||
| Service account key risks + key-less alternatives | |||
| Cloud Armor (WAF + DDoS) | |||
| Secret Manager | |||
| Binary Authorization | |||
| Chronicle SIEM + YARA-L | |||
| GCPloit / SA impersonation attacks | |||
| Metadata server SSRF (GCE) | |||
| IR: compromised SA key | |||
| IR: crypto mining on GCE |
AI / LLM Security (OWASP 2025)
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| LLM01: Prompt injection (direct + indirect) | |||
| LLM02: Sensitive information disclosure | |||
| LLM03: Supply chain (model/plugin/package) | |||
| LLM04: Data and model poisoning | |||
| LLM05: Improper output handling (XSS, SQLi, RCE) | |||
| LLM06: Excessive agency | |||
| LLM07: System prompt leakage | |||
| LLM08: Vector/embedding weaknesses | |||
| LLM09: Misinformation / hallucination risk | |||
| LLM10: Unbounded consumption / DoS | |||
| RAG architecture + indirect injection via retrieval | |||
| LLM agent privilege design (least privilege) |
Detection & Forensics
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| SIEM concepts + Splunk/Chronicle queries | |||
| IOC types (IP, hash, domain, behaviour) | |||
| YARA rule writing | |||
| Snort/Suricata signatures | |||
| Honeypots + canary tokens | |||
| Anomaly vs signature-based detection | |||
| VPC/network flow log analysis | |||
| Memory forensics (Volatility) | |||
| Disk forensics (FTK, The Sleuth Kit) | |||
| Chain of custody | |||
| Anti-forensics techniques | |||
| Malware analysis: static vs dynamic | |||
| Cyber kill chain stages | |||
| MITRE ATT&CK framework (navigation) |
Incident Management
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| PICERL phases + what happens in each | |||
| Google IMAG model | |||
| Communication in an incident (who, when, how) | |||
| Triage vs investigation vs containment distinction | |||
| Legal/privacy notification obligations | |||
| Playbook structure | |||
| Post-mortem format + blameless culture | |||
| Tabletop exercise facilitation |
Python / Coding
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| String manipulation (reverse, anagram, palindrome) | |||
| List operations (two-sum, merge sorted, rotate) | |||
| Dict patterns (counting, grouping) | |||
| Recursion (fibonacci, factorial, permutations) | |||
| Sliding window / two-pointer | |||
| Sorting with custom key | |||
| OOP: classes, inheritance, dunders | |||
| Context managers | |||
| Regex in Python | |||
| Big O — time and space | |||
| Log parser in Python | |||
| Port scanner in Python | |||
| Rate limiter implementation | |||
| HMAC / crypto primitives in Python | |||
| Python security anti-patterns (eval, pickle, shell=True) |
Threat Modelling
| Topic | Score (0–3) | Status | Notes / Gaps |
|---|---|---|---|
| STRIDE framework (all 6) | |||
| DREAD risk scoring | |||
| Data Flow Diagrams + trust boundaries | |||
| MITRE ATT&CK for threat hunting | |||
| Attack trees | |||
| PASTA methodology | |||
| Secure design principles |
Scoring Summary
Copy your scores here after each session for trend tracking.
| Date | Networking | Web App | Crypto | Auth | Linux | CI/CD | K8s | AWS | GCP | AI/LLM | Detection | Coding |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
Target before interviewaverage ≥ 2.5 across all domains; no domain below 2.