Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

All problems (753)

SECURITY-1277A CDN or reverse proxy rate limit looks strict but password spray still landsAn authentication surface keeps seeing spray attempts after per-IP limits are lowered aggressively.SecurityAdvanced16 minProSECURITY-1311A Cloudflare Access policy looks correct and one API still returns 403An internal API is moved behind a new Access application and only some users keep seeing 403 responses from a browser session that otherwise looks authenticated.SecurityAdvanced16 minProSECURITY-1318A Kubernetes admission webhook serves valid TLS and requests still failA cluster rotates webhook serving certs in place and later admission failures appear even though the pod and service remain healthy.SecurityAdvanced16 minProSECURITY-1297A rate limiter on login works against direct traffic but notA rate limiter on login works against direct traffic but not focuses on incident-response and asks the reader to isolate the key signal. A rate limiter is only as strong as the identity header or source it trusts.SecurityAdvanced16 minProSECURITY-1262A SameSite cookie setting breaks SSO only on one browser pathSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced16 minProSECURITY-1264A secret leak alert keeps returningSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced16 minProSECURITY-156A SIEM dashboard shows the new field names, but the scheduled incident export still queries the old schema and sends empty nightly reportsInteractive analysis is fine, yet one automated reporting path still depends on the legacy field map.SecurityAdvanced16 minProSECURITY-1295A signed cookie works on one subdomain and fails on anotherA cross-subdomain auth feature works on one hostname and fails only when routed through a CDN alias or alternate domain.SecurityAdvanced16 minProSECURITY-1301A Vault AppRole login succeeds and database credentials still expire earlyAn app authenticates with AppRole and later loses its dynamic credentials long before the advertised secret lifetime should end.SecurityAdvanced16 minProSECURITY-1313A Vault AppRole rollout works in staging and fails in productionA Vault AppRole rollout works in staging and fails in production focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. CIDR-bound auth often fails on hidden NAT differences rather than on Vault role misconfigu...SecurityAdvanced16 minProSECURITY-1304A WAF custom rule blocks only the canary URLA security team tunes a WAF rule for production traffic and only the canary path keeps failing with the same signature.SecurityAdvanced16 minProSECURITY-1321An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy-change)An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. OIDC loops often come from callback identity drift rather than from bad user cr...SecurityAdvanced16 minProSECURITY-121An OAuth token exchange succeeds, but the resource server clock skew rejects the just-issued JWT as not yet validIdentity is correct, yet token freshness assumptions differ across the two systems.SecurityAdvanced16 minProSECURITY-1303Cloudflare Access protects the app generally and one cached path reaches the origin without identity headersAn origin trusts CF Access headers and later one static-like route starts reaching it without the expected identity context.SecurityAdvanced16 minProSECURITY-1309mTLS resumes fine after certificate rotation on one service and fails on anotherA rotation campaign updates bundles cluster-wide and only one workload or sidecar continues failing mutual TLS handshakes.SecurityAdvanced16 minProSECURITY-1310Secret scanning alerts keep firing after rotationA team rewrites history and rotates secrets successfully, but alerts keep reappearing from what looks like a clean repository.SecurityAdvanced16 minProSECURITY-095SIEM parser update collapses two source IP fields and the threat hunt queries miss half the trafficLogs are arriving, but hunting results look incomplete because the updated parser rewrote field names that saved searches still depend on.SecurityAdvanced16 minProSECURITY-393A break-glass access role bypasses MFA (Auth and Session Failure)A break-glass access role bypasses MFA (Auth and Session Failure) focuses on Identity and Access Management and asks the reader to isolate Auth and Session Failure in Azure. 실무에서는 auth-and-session-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로...SecurityAdvanced17 minProSECURITY-357A certificate replacement installs the right chainA certificate replacement installs the right chain focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 certificate-trust-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점...SecurityAdvanced17 minProSECURITY-345A federated login trust points at the correct issuer while the downstream application still enforces the old audience or group claim mapping during a staged decommissionAuthentication succeeds at the identity edge and authorization fails where claims are interpreted differently. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced17 minPro