Week 18 · slides

Week 18

← all weeks · readme · exam


marp: true theme: default paginate: true header: "Software Security · Week 18 · Final"


Week 18

Final — Written Exam

Cumulative · emphasis on Weeks 10–16

<!-- Proctor deck. Before start: confirm exam version (rotate from exams/item-bank.md final pool), time, open/closed-note, integrity (no AI/phones). Keep talk minimal once the clock runs. -->


Format

  • Duration / open-note: (set by instructor)
  • Cumulative; weighted toward the modern-stack half

<!-- Fill the blanks aloud (e.g. 150 min). Cumulative but ~60–70% from W10–16; sections mirror the midterm (concepts / spot-vuln / applied / design). -->


What's assessed

  • Supply-chain integrity (SLSA / SBOM / Cosign)
  • Cloud / IAM least privilege
  • LLM & agentic threat modeling
  • DevSecOps gate design
  • "Spot the vuln / design the fix" across the term
  • Memory-safe-language & Secure-by-Design tradeoffs

<!-- Show briefly; matches the W17 mock. Exam day — don't teach. -->


Tips

  • Reason about design, not just single bugs
  • Always name the mitigation + where it belongs in the pipeline
  • Map to OWASP 2025 / LLM Top 10 / CWE

<!-- Key score-saver for the final: it rewards DESIGN reasoning (where the fix belongs), not just bug-spotting. Say once, then start. -->


Good luck

Week 19: capstone CTF tournament + project demos

<!-- Close: remind W19 = team CTF + graded demos; bring runnable project + SBOM/signed artifact/pipeline. Grade with exams/week18-…-answers.md. -->