4.4 What this volume does not teach
Say the boundary out loud so you do not bluff in an interview.
- This site's DevSecOps course is Volume 1 only: foundations, culture, and threat modeling on paper.
- It does not teach OWASP Top 10 fixes.
- It does not teach SAST tools, including SonarQube and Semgrep, and it has no scan commands.
- It does not teach SCA, and it does not teach SBOM formats such as CycloneDX or SPDX.
- It does not contain exploit steps, interception steps, or payload recipes. Those do not belong in a later chapter of this volume either, because those chapters are not here.
- It does not ask you to attack a payment system, a bank, or a classmate's project.
Those later names are a signpost, not a promise that a second volume is published on this website. When you meet the tools at work, bring this volume's questions with you: where is the check on the belt, which STRIDE word is this, and does the server know the real amount?
Raju leaves with the folded sheet, not a bag of commands. Guru-ji says the diploma for Volume 1 is teaching the belt to someone who has never seen it.
Keep the pocket list
- Left is cheap, right is a leak.
- Three chairs, four DORA goals, one extra scan share that is not DORA.
- 5000 must not become 1 just because a phone said so.
- Pencil first. Tools later, in a book this site does not claim to host.
If you can tell the belt story and the payment sentence without this page, Volume 1 did its job. Samajla ka? अगर बेल्ट की कहानी और पेमेंट वाला वाक्य बिना इस पन्ने के आ जाता है, तो यह खंड पूरा है.