Demo case file · Technical
Payments company
Security Engineer
This is a demo case file: a realistic example written from commonly known interview formats, not a real candidate's interview experience.
Questions asked
- Threat-model a password-reset flow that emails the user a link.
- Here is a function that builds a SQL query from user input. Find the vulnerabilities and fix them.
- A developer's cloud access key was pushed to a public repository an hour ago. What do you do, in order?
What to expect
Threat modelling was open-ended; they wanted token entropy, expiry, single use, and not revealing whether an email address has an account. The incident question was about ordering: revoke the key first, then check logs for what it was used for, then clean up history and fix the process.
Practice this exact interview.
Mockd plays the interviewer live, using these questions and notes, then grades your answers.
Start a practice session Browse all case files