Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

All problems (753)

SECURITY-118A hardware token step-up is required on paper, but the mobile fallback policy silently downgrades privileged actions to SMSAdministrators believe strong authentication protects the action, yet one fallback rule lets the mobile app satisfy the control with a weaker factor.SecurityAdvanced17 minProSECURITY-375A reverse proxy or isolation layer protects browser trafficA reverse proxy or isolation layer protects browser traffic focuses on WAF and AppSec Controls and asks the reader to isolate Permission Denied in NGINX. 실무에서는 permission-denied 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. WAF / AppSec 관점...SecurityAdvanced17 minProSECURITY-1299A service mesh identity update looks correct but one gateway rejects mTLSA workload migration between trust domains succeeds broadly and one ingress or egress gateway alone starts rejecting mTLS peers.SecurityAdvanced17 minProSECURITY-1285A service mesh mTLS policy looks identical across namespaces but one namespace still failsA mesh-wide trust update succeeds broadly and one namespace alone begins failing mTLS handshakes immediately afterward.SecurityAdvanced17 minProSECURITY-110A SIEM correlation rule misses an after-hours brute-force chainRaw events arrive, but the analytic never fires because time bucketing no longer aligns with the intended incident window.SecurityAdvanced17 minProSECURITY-125A SIEM suppression for the vulnerability scanner hides real lateral movementNoise reduction worked for one source, but the coarse suppression pattern now covers genuine malicious activity.SecurityAdvanced17 minProSECURITY-105A WAF bypass exception for health checks accidentally matches the admin route prefix after a path refactorMonitoring stays green, but a protection hole opens because the relaxed path rule now overlaps with privileged endpoints.SecurityAdvanced17 minProSECURITY-143A WAF custom rule matches on decoded path segments, but the reverse proxy evaluates the raw form and one legacy route stays bypassableBoth layers inspect the request, yet they do not interpret the path in the same representation.SecurityAdvanced17 minProSECURITY-1293A WAF rule tuned for the main hostname still blocks the canary pathA canary environment behind the same WAF behaves differently even after the rule was tuned against production traffic.SecurityAdvanced17 minProSECURITY-1279An intermediate certificate is installed on the server, but older clients still failA certificate incident appears fixed by file inspection and only certain client families continue to fail.SecurityAdvanced17 minProSECURITY-092Cloud WAF blocks the admin API path only after a new JSON field increases rule score above thresholdThe endpoint worked before, but the updated payload shape now trips a scoring-based rule model that was previously below the block threshold.SecurityAdvanced17 minProSECURITY-102Just-in-time admin approval succeeds, but the bastion PAM cache still enforces the previous group membershipOperators receive the right entitlement in the identity plane, yet the bastion keeps denying access until its local authorization cache expires.SecurityAdvanced17 minProSECURITY-109SCIM deprovision disables the SaaS account, but a long-lived personal token still lets the former admin call the APIIdentity offboarding appears complete in the UI, yet API access remains because one token type was never linked to account lifecycle enforcement.SecurityAdvanced17 minProSECURITY-330A break-glass or emergency path bypasses one identity control while another session or device rule still revokes it before the task finishes during a failover rehearsalThe emergency door opens and another control closes it before recovery is done. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-1231A browser login loop persists after successful OIDC callbackOne hostname or browser completes the login flow and another loops forever even though the provider logs show success.SecurityAdvanced18 minProSECURITY-1283A certificate bundle looks current on disk but one Java client still failsA certificate bundle looks current on disk but one Java client still fails focuses on protocol-interoperability and asks the reader to isolate the key signal. Trust material correctness depends on the verifier's path-building behavior,...SecurityAdvanced18 minProSECURITY-228A custom WAF response hides the real block reason while upstream retries amplify the same exploit attempt internally during a failover rehearsalThe control works and one observability decision turns it into operational noise. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-160A ransomware isolation workflow snapshots the volumes correctly, but the snapshot retention tag is missing and cleanup automation deletes the evidence before triage startsContainment worked, yet incident preservation failed because the evidence path lacked lifecycle protection.SecurityAdvanced18 minProSECURITY-1275A WAF tune fixes the primary hostname but the same application still fails on a second hostnameA false positive fix is validated on the main public route and users still break through a legacy or alternate hostname.SecurityAdvanced18 minProSECURITY-168An emergency account bypasses the first control while a downstream session rule still revokes it too early during a failover rehearsalThe break-glass path escapes one identity gate and remains constrained by another. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minPro