정보보안기사
753 incident response problems that help with 정보보안기사 prep.
먼저 읽을 가이드
추천 문제
All problems (753)
SECURITY-1558A certificate pin set is refreshed and one mobile API still breaksOnly resumed mobile sessions fail certificate pinning after a chain refresh.SecurityAdvanced12 minProSECURITY-1460A machine identity rotates and pooled outbound TLS sessions keep failingA machine identity rotates and pooled outbound TLS sessions keep failing focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Credential rotation can fail in connection pools that treat TLS session state as...SecurityAdvanced12 minProSECURITY-1489A Vault agent rotates a certificate and the app still presents the old oneCertificate rotation succeeds in Vault and the application keeps serving the previous certificate until restart.SecurityAdvanced12 minProSECURITY-1551An Elastic detection rule is updated and one index set still misses alertsAlerts disappear only for one log family after detection rule updates.SecurityAdvanced12 minProSECURITY-1490An Envoy mTLS path validates new CRLs and one cluster still accepts revoked certsRevoked certificates continue to pass on one cluster after CRL rotation while others reject them correctly.SecurityAdvanced12 minProSECURITY-1500An mTLS allowlist updates and one service still trusts the retired client CAOne service continues trusting a retired client CA after an mTLS allowlist rotation.SecurityAdvanced12 minProSECURITY-1510An mTLS allowlist updates and one service still trusts the retired client CAOne service continues trusting a retired client CA after allowlist rotation.SecurityAdvanced12 minProSECURITY-1520An mTLS allowlist updates and one service still trusts the retired client CAOne service continues trusting a retired client CA after allowlist rotation.SecurityAdvanced12 minProSECURITY-1530An mTLS allowlist updates and one service still trusts the retired client CAOne service still trusts a retired client CA after allowlist rotation.SecurityAdvanced12 minProSECURITY-1560An mTLS service policy is narrowed and one sidecar still trusts the retired client bundleOne sidecar still trusts retired clients after narrowing mTLS policy.SecurityAdvanced12 minProSECURITY-1418A high-severity Elastic SIEM rule goes quietA high-severity Elastic SIEM rule goes quiet focuses on schema-migration and asks the reader to isolate the key signal in elastic. Field names surviving a migration do not guarantee their meanings stayed identical for detection logic.SecurityAdvanced13 minProSECURITY-1458A load balancer failover keeps client cert auth green and later breaks itA load balancer failover keeps client cert auth green and later breaks it focuses on redundancy and asks the reader to isolate the key signal in palo-alto. Failover breaks in certificate auth can hide in responder cache state rather than...SecurityAdvanced13 minProSECURITY-1408A SIEM rule meant to catch admin abuse goes quietA SIEM rule meant to catch admin abuse goes quiet focuses on schema-migration and asks the reader to isolate the key signal in elastic. Detection rules often fail after schema migrations because the underlying events are present under new fi...SecurityAdvanced13 minProSECURITY-1398An Elastic detection rule misses admin abuseAn Elastic detection rule misses admin abuse focuses on incident-response and asks the reader to isolate the key signal in Opensearch. Detection quality can degrade when schema evolution changes relationships between actor and target fie...SecurityAdvanced13 minProSECURITY-1388An Elastic detection rule still misses one attacker pathAn Elastic detection rule still misses one attacker path focuses on incident-response and asks the reader to isolate the key signal in Opensearch. Detection drift often follows schema normalization changes rather than event loss.SecurityAdvanced13 minProSECURITY-1448An Elastic SIEM rule goes quietIngest is healthy and one critical admin-abuse rule silently stops firing after an ECS migration.SecurityAdvanced13 minProSECURITY-1438An Elastic SIEM rule goes quiet (siem-correlation-followed-legacy-field-after-semantic-drift)An Elastic SIEM rule goes quiet (siem-correlation-followed-legacy-field-after... focuses on schema-migration and asks the reader to isolate the key signal in elastic. Schema migrations can preserve field names while changing what th...SecurityAdvanced13 minProSECURITY-1428An Elastic SIEM rule goes quiet (siem-rule-followed-legacy-field-after-semantic-drift)An Elastic SIEM rule goes quiet (siem-rule-followed-legacy-field-after... focuses on schema-migration and asks the reader to isolate the key signal in elastic. Field presence after a schema migration does not guarantee the field still mean...SecurityAdvanced13 minProSECURITY-1369An Ubuntu bastion patch run completes and SSH trust breaksRoutine patching succeeds and later automated SSH clients start rejecting the bastion even though no access policy was intentionally changed.SecurityAdvanced13 minProSECURITY-1381A Cloudflare mTLS policy protects the main API and one versioned path stays...A Cloudflare mTLS policy protects the main API and one versioned path stays... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Edge auth failures often come from precedence between broad exceptions a...SecurityAdvanced14 minPro