Week 18
← all weeks · readme · exam
marp: true theme: default paginate: true header: "Software Security · Week 18 · Final"
Week 18
Final — Written Exam
Cumulative · emphasis on Weeks 10–16
<!-- Proctor deck. Before start: confirm exam version (rotate from exams/item-bank.md final pool), time, open/closed-note, integrity (no AI/phones). Keep talk minimal once the clock runs. -->
Format
- Duration / open-note: (set by instructor)
- Cumulative; weighted toward the modern-stack half
<!-- Fill the blanks aloud (e.g. 150 min). Cumulative but ~60–70% from W10–16; sections mirror the midterm (concepts / spot-vuln / applied / design). -->
What's assessed
- Supply-chain integrity (SLSA / SBOM / Cosign)
- Cloud / IAM least privilege
- LLM & agentic threat modeling
- DevSecOps gate design
- "Spot the vuln / design the fix" across the term
- Memory-safe-language & Secure-by-Design tradeoffs
<!-- Show briefly; matches the W17 mock. Exam day — don't teach. -->
Tips
- Reason about design, not just single bugs
- Always name the mitigation + where it belongs in the pipeline
- Map to OWASP 2025 / LLM Top 10 / CWE
<!-- Key score-saver for the final: it rewards DESIGN reasoning (where the fix belongs), not just bug-spotting. Say once, then start. -->
Good luck
Week 19: capstone CTF tournament + project demos
<!-- Close: remind W19 = team CTF + graded demos; bring runnable project + SBOM/signed artifact/pipeline. Grade with exams/week18-…-answers.md. -->