Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

All problems (753)

SECURITY-1376A fail2ban-style parser sees every request as the CDN edgeA proxy trust configuration is updated and later automated bans begin hitting CDN edges or harmless intermediaries instead of abusive clients.SecurityAdvanced14 minProSECURITY-1411An access proxy protects `/api/users` and one service endpoint still bypasses...An access proxy protects `/api/users` and one service endpoint still... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Access regressions often come from route precedence and norm...SecurityAdvanced14 minProSECURITY-1421An access proxy protects the user API and one service endpoint still bypasses...An access proxy protects the user API and one service endpoint still... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Access regressions often come from route precedence and no...SecurityAdvanced14 minProSECURITY-1431An access proxy protects the user API and one service path still bypasses MFAAn access proxy protects the user API and one service path still bypasses MFA focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Access regressions often come from route pr...SecurityAdvanced14 minProSECURITY-1441An access proxy protects the user API and one service path still bypasses...An access proxy protects the user API and one service path still bypasses... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Access regressions often come from route pre...SecurityAdvanced14 minProSECURITY-1363An Elastic API key rotation is successful and one Beats sidecar still failsCredential rotation finishes and later one ingestion path continues to return 401 despite the new secret being present in the cluster.SecurityAdvanced14 minProSECURITY-1393An OpenSearch admin SSO flow returns successfully and session validation failsAn OpenSearch admin SSO flow returns successfully and session validation fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. JWT validation issues after key rotation often live in intermediate JWKS cache...SecurityAdvanced14 minProSECURITY-1383An OpenSearch snapshot repository remains registered and backups failAn OpenSearch snapshot repository remains registered and backups fail focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Repository auth failures can persist after IAM fixes when the node keeps pre...SecurityAdvanced14 minProSECURITY-1359An Ubuntu bastion patch window completes and SSH trust breaksAn Ubuntu bastion patch window completes and SSH trust breaks focuses on Identity And Access and asks the reader to isolate the key signal in Linux. Patch windows can rotate machine identity, not just patch packages.SecurityAdvanced14 minProSECURITY-1349An Ubuntu bastion patch window succeeds and SSH trust breaksRoutine patching is completed and later automated SSH clients reject the bastion despite no intended access control changes.SecurityAdvanced14 minProSECURITY-1386A Cilium deny policy looks correct and one egress path remains openA Cilium deny policy looks correct and one egress path remains open focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Policy surprises often come from broader selectors attached through helper layers lik...SecurityAdvanced15 minProSECURITY-1357A Cilium FQDN policy allows a hostname and still blocks trafficA Cilium FQDN policy allows a hostname and still blocks traffic focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Name-based policy is only as correct as the DNS query that actually leaves the worklo...SecurityAdvanced15 minProSECURITY-1377A Cilium FQDN policy allows the expected hostname and traffic still failsA Cilium FQDN policy allows the expected hostname and traffic still fails focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. FQDN policies operate on real DNS observations, not on the hostname stri...SecurityAdvanced15 minProSECURITY-1336A Cilium network policy blocks unexpected egress only in one security...A Cilium network policy blocks unexpected egress only in one security... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Name-based policy decisions can stale independently from pod label...SecurityAdvanced15 minProSECURITY-1347A Cilium policy allows one FQDN and still breaks egressA secure namespace uses a service mesh sidecar and later one external dependency fails only under FQDN-based egress controls.SecurityAdvanced15 minProSECURITY-1345A Cloudflare Access protected app still exposes a management portA Cloudflare Access protected app still exposes a management port focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cloudflare. Zero Trust at the front door does not automatically secure alternate p...SecurityAdvanced15 minProSECURITY-1334A CrowdSec or Fail2ban style ban pipeline blocks the wrong sourceA CrowdSec or Fail2ban style ban pipeline blocks the wrong source focuses on incident-response and asks the reader to isolate the key signal in NGINX. Security controls that depend on source IP must be reviewed whenever the trust bo...SecurityAdvanced15 minProSECURITY-1308A CSP nonce implementation is correct at origin and still unsafeA team adds CSP nonces and later a cached HTML shell makes the same nonce appear repeatedly in production.SecurityAdvanced15 minProSECURITY-1317A GitHub Actions secret scan starts failing only forked pull requestsA GitHub Actions secret scan starts failing only forked pull requests focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Workflow security failures are often ordering bugs, not missing secret definitions.SecurityAdvanced15 minProSECURITY-1312A Grafana datasource secret rotates successfully and alert rules still failA team rotates monitoring credentials and later finds dashboards healthy while rule evaluations continue to fail with auth errors.SecurityAdvanced15 minPro