Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

All problems (753)

SECURITY-1341A Grafana SSO login succeeds and folder permissions look emptyA company refreshes its IdP schema and later Grafana users log in successfully but lose access to folders they previously owned.SecurityAdvanced15 minProSECURITY-1371A Grafana SSO login succeeds and users land as ViewersAn IdP claim cleanup lands and later every Grafana login works but the expected team roles stop being assigned.SecurityAdvanced15 minProSECURITY-1305A Palo Alto URL allow rule exists and users still see a block pageA URL is explicitly allowed and users still cannot reach it through one firewall path after a decryption policy change.SecurityAdvanced15 minProSECURITY-1380A Terraform-managed OIDC trust update is applied and one workspace still...A Terraform-managed OIDC trust update is applied and one workspace still... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Remote runners can retain assumptions about trust material even...SecurityAdvanced15 minProSECURITY-1320A WAF blocks only one JSON API (waf-header-normalization-breaks-one-api-client)A WAF blocks only one JSON API (waf-header-normalization-breaks-one-api... focuses on protocol-interoperability and asks the reader to isolate the key signal in Cloudflare. Parser changes can surface client quirks that were always present but pr...SecurityAdvanced15 minProSECURITY-1339A WAF challenge policy protects the main app and still exposes one admin routeA WAF challenge policy protects the main app and still exposes one admin route focuses on Deployment Governance and asks the reader to isolate the key signal in NGINX. Security includes can look global while still missing routes defined in separate...SecurityAdvanced15 minProSECURITY-1330A zero trust policy allows the service token and the backend still returns 403A zero trust policy allows the service token and the backend still returns 403 focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Zero Trust success at the edge does not guarantee the origin app...SecurityAdvanced15 minProSECURITY-1327An admission policy rollout breaks only one namespaceAn admission policy rollout breaks only one namespace focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Distributed trust injection systems rarely converge everywhere at the same instant.SecurityAdvanced15 minProSECURITY-1350An AWS OIDC trust policy matches the cluster issuer and one controller still...An AWS OIDC trust policy matches the cluster issuer and one controller... focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared IaC can still emit stale identity data if one workspace cached old metadata.SecurityAdvanced15 minProSECURITY-1360An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity maintenance task succeeds broadly and later one controller in one environment alone continues failing IRSA or web-identity auth.SecurityAdvanced15 minProSECURITY-1370An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity refresh completes and later only one environment continues to fail IRSA or web-identity auth for a controller.SecurityAdvanced15 minProSECURITY-1315An AWS STS AssumeRoleWithWebIdentity call works from one workload and fails...An AWS STS AssumeRoleWithWebIdentity call works from one workload and fails... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. STS web identity failures often come from audience mismatch even when issuer and subje...SecurityAdvanced15 minProSECURITY-1340An AWSKRUG-style EKS access pattern uses OIDC and still breaks one controllerAn AWSKRUG-style EKS access pattern uses OIDC and still breaks one controller focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared Terraform code can still render different identity assumptions if...SecurityAdvanced15 minProSECURITY-1353An Elastic API key rotates successfully and one Beats sidecar keeps 401ingA credential rotation is completed and later one logging path continues to fail even though the secret update is visible in the cluster.SecurityAdvanced15 minProSECURITY-1331An Elastic API key rotation succeeds and one Beats pipeline still gets 401An Elastic API key rotation succeeds and one Beats pipeline still gets 401 focuses on Identity And Access and asks the reader to isolate the key signal in Linux. Key rotation success in storage does not prove the runtime consumer has...SecurityAdvanced15 minProSECURITY-1343An Elastic ingest pipeline keeps 401ing (elastic-sidecar-kept-using-projected-old-api-key-volume)An Elastic ingest pipeline keeps 401ing (elastic-sidecar-kept-using-projected... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Cluster secret updates do not automatically mean every pod reop...SecurityAdvanced15 minProSECURITY-1329An IdP secret rotation succeeds and one workload still failsAn OIDC signing key is rotated and only one service path keeps rejecting freshly minted tokens for a while afterward.SecurityAdvanced15 minProSECURITY-1372An OpenSearch dashboard SSO flow works on GET and failsAn OpenSearch dashboard SSO flow works on GET and fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Cross-site POST returns are especially sensitive to SameSite policy changes around proxy and...SecurityAdvanced15 minProSECURITY-1332An OpenSearch role mapping looks correct and SSO users still lose accessAn OpenSearch role mapping looks correct and SSO users still lose access focuses on Deployment Governance and asks the reader to isolate the key signal in Linux. An auth token can contain the right roles under the wrong shape for a plugin th...SecurityAdvanced15 minProSECURITY-1324An SSH certificate rollout is correct and clients still choose the wrong identityA certificate-based SSH migration is rolled out and some users still fail even though the correct certificate is present in their environment.SecurityAdvanced15 minPro