정보보안기사
753 incident response problems that help with 정보보안기사 prep.
먼저 읽을 가이드
추천 문제
All problems (753)
SECURITY-399Containment isolates egress from compromised hosts while the forensic image or memory capture workflow still depends on an outbound escrow service during a staged decommissionThe incident is contained and the evidence pipeline quietly breaks. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced18 minProSECURITY-078JIT provisioning creates duplicate accounts after the immutable identity key changesFederation remains healthy, but every login now spawns another local account because the stable identity key changed from email to a new immutable identifier.SecurityAdvanced18 minProSECURITY-1261JWT verification breaks after key rotationSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced18 minProSECURITY-1266JWT verification breaks after key rotationA planned key rotation is executed cleanly and one application still begins rejecting newly signed tokens.SecurityAdvanced18 minProSECURITY-1258mTLS appears configured correctly but some clients still failOne client library connects to a service successfully while another fails with trust errors against the same endpoint.SecurityAdvanced18 minProSECURITY-094mTLS handshake succeeds to the proxy but upstream certificate pinning breaks only on one pathThe edge trust path looks correct, yet the service still fails because an internal hop enforces a different certificate identity contract.SecurityAdvanced18 minProSECURITY-1265mTLS succeeds for one hostname but fails for another on the same serviceSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced18 minProSECURITY-1270mTLS succeeds for one hostname but fails for another on the same serviceA service behind one proxy works for its main hostname and starts failing trust or hostname checks on another alias.SecurityAdvanced18 minProSECURITY-1273One hostname behind the same proxy passes mTLS while another failsA service behind one proxy works on its primary hostname and fails on an alternate alias that was assumed to be equivalent.SecurityAdvanced18 minProSECURITY-085Session revocation works centrally but one edge node continues accepting the old JWT until its cache expiresThe revoke event is recorded correctly, yet some requests still succeed because one verifier node has not refreshed its token or key cache.SecurityAdvanced18 minProSECURITY-091SSO works but step-up MFA never triggersPrimary authentication succeeds, yet privileged actions remain exposed because the application is still reading an outdated assurance claim.SecurityAdvanced18 minProSECURITY-1215Temporary WAF bypass is removed centrally but one edge path still behaves as if the exception remainsThe source of truth is clean, yet traffic still flows through an old exception because rollout state diverged across edge nodes or configs.SecurityIntermediate18 minProSECURITY-139The reverse proxy and WAF normalize duplicate headers differently, creating a request-smuggling edge case on one legacy routeMost paths are safe, but one parsing mismatch keeps a classic multi-hop ambiguity alive.SecurityAdvanced18 minProSECURITY-174Two request-processing layers normalize the same input differently and one legacy route stays bypassable during a failover rehearsalMultiple security layers inspect the request and disagree on what the request really is. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-1224WAF rollback looks complete but one hostname still enforces the old ruleA temporary block is reverted and most traffic returns to normal, but one API hostname still rejects the old pattern.SecurityAdvanced18 minProSECURITY-1219WAF rule rollback looks complete but one API hostname still enforces the old behaviorA temporary block is reverted and most traffic returns to normal, but one API hostname still rejects the old pattern.SecurityAdvanced18 minProSECURITY-1263A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers-different-waf-signals)A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Azure. A WAF rule tuned for one header and proxy shape can still fail on alternate h...SecurityAdvanced19 minProSECURITY-1268A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers-different-waf-signals)A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Azure. A WAF rule tuned for one header and proxy shape can still fail on alternate h...SecurityAdvanced19 minProSECURITY-1259An allowlist protects the main admin hostname but a second hostname still reaches the same backend through another proxy chainThe edge policy works on the documented URL, yet another hostname bypasses it because the backend is still exposed through a different path.SecurityAdvanced19 minProSECURITY-081Conditional Access excludes the break-glass user but not the device-registration prerequisiteThe emergency account is excluded from the main policy, yet login still fails because an upstream prerequisite step is governed by a different device rule set.SecurityAdvanced19 minPro