CogitaveLearn

Knowledge check

Check your knowledge

Choose an answer to see why it is right or wrong.

JavaScript is off, so every explanation is shown at once.

  1. 01A design describes IAM (SSO, OIDC, agent capability grants) and also the process for running a threat model at the design gate. Which standard owns which, per Cogitave?

  2. 02A change adds a new external HTTP interface with a new authentication path. Is a threat model optional here?

  3. 03In the request lifecycle, what do the two Definition-of-Done security gates, S1 and S2, enforce?

  4. 04A dependency finding scores CVSS 6.5 (Medium), but its EPSS exploit probability is 0.7. How does the SLA change?