GradePack

    • Home
    • Blog
Skip to content
bg
bg
bg
bg

Author Archives: Anonymous

A Ridgeline Grid substation loses its primary network link t…

A Ridgeline Grid substation loses its primary network link to the regional control center during a fiber outage. Rather than failing outright, the substation buffers its telemetry locally and switches to a cellular backup link, resuming full reporting once the fiber is restored. Which named tolerance does this illustrate, and under which subordinate attribute?

Read Details

Ridgeline Grid’s substation-alerting module has a single cla…

Ridgeline Grid’s substation-alerting module has a single class responsible for validating sensor readings, formatting alert messages, sending emails, logging to disk, and updating the operator dashboard — five distinct responsibilities in one class, each usable independently by only a small part of the module. A new developer is asked to reuse just the email-sending logic elsewhere in the codebase and finds it painful to extract cleanly. Which of the following are genuine consequences of this kind of design? (Select all that apply.)

Read Details

Ridgeline Grid’s original substation-monitoring software has…

Ridgeline Grid’s original substation-monitoring software has a hard-coded limit of 200 simultaneous sensor connections, written directly into the source code. As the company adds substations, operators now have to file a change request and wait for a code change and redeploy every time the limit needs raising. A capacity-planning consultant recommends externalizing that limit into a configuration file operators can edit directly. What NFR-driven technique does this recommendation illustrate?

Read Details

A Nordholm Systems engineer proposes dropping fuzz testing f…

A Nordholm Systems engineer proposes dropping fuzz testing from the verification checklist, pointing out it’s used far less than almost anything else the team does. Before agreeing, the security lead checks how engineers rate fuzz testing’s impact when they do use it — and finds it rated meaningfully more impactful than dynamic analysis, a much more similar-sounding activity that also sees low use. What best explains fuzz testing’s rare use despite its comparatively strong impact rating?

Read Details

Nordholm Systems’ security lead pulls together data across t…

Nordholm Systems’ security lead pulls together data across the company’s dozen agile teams and finds a pattern that puzzles her: activities the teams use most often are, on average, rated by the very engineers using them as only moderately impactful on security — while some activities used far less often are rated as highly impactful. A colleague asks what would cause usage rates and perceived impact to diverge like that. What best explains the divergence?

Read Details

At Nordholm Systems, a team lead proposes moving the project…

At Nordholm Systems, a team lead proposes moving the project’s threat-modeling and secure-design work from its current spot — right before release — to the very start of each feature’s development, even though it means more up-front discussion time. A skeptical colleague argues this is just extra process for no real benefit. True or False: moving this work earlier in the cycle is likely to make it more effective, not less.

Read Details

Trellis Health’s Scrum team has finished implementing a pati…

Trellis Health’s Scrum team has finished implementing a patient-scheduling story. The developer marks it “done” because the feature works exactly as the acceptance criteria describe. A security reviewer flags it anyway: the story’s Definition of Done never mentioned encryption, session timeout, or audit logging, so none of that was checked. Whose omission is actually responsible for this gap?

Read Details

Nordholm Systems’ verification-phase practices span a wide r…

Nordholm Systems’ verification-phase practices span a wide range: automated testing tools, manual code reviews, dedicated security test cases, penetration testing, and more. When the security lead asks which single practice her engineers both use the most and rate as most impactful for security, one activity stands out clearly above the rest. Which one, and why does that pairing matter?

Read Details

Nordholm Systems’ security lead ranks the company’s design-p…

Nordholm Systems’ security lead ranks the company’s design-phase security activities by how often teams actually do them. Application security configuration comes out on top for sheer frequency of use — yet when the same engineers rate how much it helps security, it scores among the lowest of any design-phase activity. Meanwhile design requirements and abuse-or-misuse cases are both used often *and* rated as genuinely high-impact. Which of the following statements holds up against that pattern? (Select all that apply.)

Read Details

At Nordholm Systems’ next retrospective, the team compares i…

At Nordholm Systems’ next retrospective, the team compares its implementation-phase practices: coding standards are followed almost universally and engineers consistently rate them as one of the most valuable security practices they use, while more specialized security tooling sees much lower adoption. A new hire asks why something as basic as a coding standard would rate above dedicated security tools. What’s the likely explanation?

Read Details

Posts pagination

Newer posts 1 2 3 4 5 … 95,376 Older posts

GradePack

  • Privacy Policy
  • Terms of Service
Top