Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

All problems (753)

NET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warningNET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warning is a hands-on troubleshooting drill. Check the certificate's expiry date against the current time. TLS and Certificate Chain needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedSecurityBeginner3 minFreeCORS error: No 'Access-Control-Allow-Origin' header is presentCORS error: No 'Access-Control-Allow-Origin' header is present is a hands-on troubleshooting drill. Read the most common CORS error and decide which side has to change. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, and the current live signal b...ReviewedSecurityBeginner3 minFree403 Forbidden: login works but one admin action is refused (vs 401)403 Forbidden: login works but one admin action is refused (vs 401) is a hands-on troubleshooting drill. Tell authentication failures (401) from authorization failures (403). Identity And Access needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedSecurityBeginner3 minFreeWARNING: UNPROTECTED PRIVATE KEY FILE: SSH refused on a new laptopWARNING: UNPROTECTED PRIVATE KEY FILE: SSH refused on a new laptop is a hands-on troubleshooting drill. Understand why ssh ignores a private key whose permissions are too open. Identity And Access needs to be checked by narrowing scope, recent change, and the current live sign...ReviewedSecurityBeginner3 minFreejwt expired (401): every request fails after about an hour in the appjwt expired (401): every request fails (Auth and Session Failure) is a hands-on troubleshooting drill. Recognise token expiry and the missing refresh step. token-validation needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서...ReviewedSecurityBeginner3 minFreeMixed Content: a chat widget disappears after switching to HTTPSMixed Content: a chat widget disappears (WAF and AppSec Controls) is a hands-on troubleshooting drill. Recognise mixed-content blocking. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 operationa...ReviewedSecurityBeginner3 minFreeSECURITY-033Managed WAF rule blocks a legitimate JSON admin requestThe API works for most clients, but a large or nested admin payload trips a managed protection rule and looks like an application bug at first glance.ReviewedSecurityIntermediate20 minFreeSECURITY-058OAuth device code session remains active after user offboardingThe user account is disabled, but a previously authorized device code flow keeps working because token revocation and downstream session invalidation were not linked tightly enough.ReviewedSecurityIntermediate20 minFreeSECURITY-034TLS renewal updates the leaf certificate but leaves the intermediate chain staleModern browsers appear fine on one path, yet API clients and internal services fail because the server still presents an incomplete chain after renewal.ReviewedSecurityIntermediate21 minFreeSECURITY-001The SSH management path is blocked after an overly narrow allowlist changeA situation where the access-control policy looks correct, but one jump-host range is missing, so the actual operations management path is blocked.ReviewedSecurityBeginner16 minFreeSECURITY-1611A login page is correct and one callback still failsOne OAuth callback still fails after moving to a new subdomain.ReviewedSecurityBeginner6 minFreeSECURITY-1614A certificate is rotated and one client still rejects itOne client still rejects a rotated certificate.ReviewedSecurityBeginner7 minFreeSECURITY-1615A JWT issuer is updated and one verifier still rejects tokensOne verifier still rejects tokens after issuer cleanup.ReviewedSecurityBeginner7 minFreeSECURITY-1613A WAF rule is relaxed and one API call still gets 403One API call still gets 403 after relaxing a WAF rule.ReviewedSecurityBeginner7 minFreeSECURITY-039S3 server access log archive fails after object ownership policy changedCentral logging was working until bucket ownership controls changed, and now write attempts fail even though the destination bucket still exists and the prefix is correct.SecurityIntermediate19 minFreeSECURITY-052ACME HTTP-01 renewal failsTLS worked yesterday, but automated renewal now fails because the well-known challenge route is treated like an untrusted request pattern by the current edge policy.SecurityIntermediate20 minFreeSECURITY-097Conditional access trusts the compliant device claim but the token was minted before the device fell out of complianceThe policy is sound, yet a risky session survives because token lifetime outlasts the compliance state transition the team expected to revoke it instantly.SecurityIntermediate15 minFreeSECURITY-152A browser isolation policy renders the admin portal remotely, but a direct-download allowlist still lets CSV exports bypass the isolated sessionThe riskiest interaction is protected, yet a side path still leaks the sensitive payload.SecurityIntermediate16 minFreeSECURITY-146A SIEM parser now splits IPv6 addresses and ports correctly, but one detection rule still assumes IPv4 colon counts and silently stops matchingThe data quality improved, yet one analytic depended on the previous broken representation.SecurityIntermediate16 minFreeSECURITY-077Custom WAF allow rule matches but a later managed rule still blocks the requestThe operator sees the expected custom rule fire, yet traffic remains blocked because the final decision is made by a later managed rule with stronger action priority.SecurityIntermediate16 minFree