Skip to main content

All weeks · Overview · Exam paper

Week 18 · Lecture slides

Week 18

Contents5 sections

Final — Written Exam

Cumulative · emphasis on Weeks 10–15


Format

  • Duration: 150 minutes · 100 pts
  • Cumulative, emphasis Weeks 10–15 (Week 16 capstone is not separately examined)
  • 4 sections: A Modern-stack concepts (30) · B Spot the Vuln (20) · C Applied (30) · D Design & DevSecOps (20)

What's assessed

A thin foundation band (Weeks 1-6, lighter weight) plus a wide emphasis band (Weeks 10-15, most of the exam weight: BOLA/mass-assignment/rate-limits, memory safety, SLSA/SBOM/Cosign, cloud IAM, prompt injection, DevSecOps gates) — Week 16 capstone isn't examinable. Section A (30, modern-stack concepts) and B (20, spot-the-vuln) test recall; C (30, applied design, no payload required) and D (20, pipeline/incident design) test design reasoning — 50/50. Unlike Week 8's midterm, which devoted 30 points to writing an actual SQL injection payload, Week 18 requires zero points of payload-writing: the shift is from writing exploits to designing fixes.


Tips

  • Reason about design, not just single bugs
  • Always name the mitigation + where it belongs in the pipeline
  • Map every finding to OWASP 2025 / API Security Top 10 / LLM Top 10 / CWE

Good luck

Week 19: capstone CTF tournament + project demos

All weeks in Software Security