정보보안기사
753 incident response problems that help with 정보보안기사 prep.
먼저 읽을 가이드
추천 문제
All problems (753)
SECURITY-1214CSP looks right but federated login popup still failsA CSP hardening change seems safe until popup or embedded identity flows start failing for some users.SecurityAdvanced19 minProSECURITY-1243mTLS appears correct but one client still failsOne runtime image connects successfully while another fails mTLS against the same upstream even though both trust the same root.SecurityAdvanced19 minProSECURITY-1233mTLS looks configured correctly but one client still failsOne client image connects successfully while another fails to complete the mutual TLS handshake against the same service.SecurityAdvanced19 minProSECURITY-1253mTLS looks correct but one client still failsOne runtime image connects successfully while another fails against the same upstream despite sharing the same root trust.SecurityAdvanced19 minProSECURITY-1248mTLS looks correct on paper but one client still failsOne client runtime connects successfully while another fails against the same upstream despite using the same trusted root set.SecurityAdvanced19 minProSECURITY-1228mTLS trust looks correct but one client still failsA service-to-service connection works from one client image and fails from another despite apparently identical certificates.SecurityAdvanced19 minProSECURITY-088Mutual TLS is enabled but the CRL endpoint is unreachable and only strict clients reject the serverCertificates are otherwise valid, but some clients fail because they require revocation checking and the CRL distribution path is no longer reachable.SecurityAdvanced19 minProSECURITY-1216Secure cookie and redirect settings look correct but one browser still loopsFederated login works in one hostname path but another branded hostname falls into a redirect loop after successful auth.SecurityAdvanced19 minProSECURITY-074Secure proxy strips WebSocket auth headers and the browser terminal stops connectingRegular HTTP browsing still works, but the interactive terminal path fails because the proxy policy handles upgraded connections differently from standard requests.SecurityAdvanced19 minProSECURITY-1218Abuse detection misses distributed attacksAn application sometimes receives traffic through the CDN and sometimes directly, but logging logic always trusts the forwarded IP header.SecurityAdvanced20 minProSECURITY-1223Abuse detection misses distributed attacksAn application sometimes receives traffic via CDN and sometimes directly, but the detector always trusts the same forwarded header.SecurityAdvanced20 minProSECURITY-1249An admin surface seems protected by an edge allowlist but an alternate hostname still bypasses it through another proxy chainThe main route is locked down, yet the same backend remains reachable through a secondary hostname that never traverses the allowlisted edge path.SecurityAdvanced20 minProSECURITY-1244An edge allowlist looks correct but an alternate hostname still exposes the admin surfaceA team secures the public admin entry and later finds an internal or legacy hostname still exposes it without the same edge restrictions.SecurityAdvanced20 minProSECURITY-1254An edge allowlist seems correct but an alternate hostname still bypasses it through another proxy chainThe main route is protected, yet the same backend remains reachable through a secondary hostname that never traverses the allowlisted edge path.SecurityAdvanced20 minProSECURITY-1234An edge allowlist seems correct but one alternate hostname still exposes the admin surfaceA team locks down an admin interface and later discovers an internal or legacy hostname still reaches the same endpoint without the edge policy.SecurityAdvanced20 minProSECURITY-1229An IP allowlist is present at the edge but admin traffic still leaks throughThe team secures the public hostname and later discovers an alternate internal or legacy hostname still exposes the same admin interface.SecurityAdvanced20 minProSECURITY-1185AWS security group looks correct but EKS API access still failsA team follows networking advice from public threads and proves the API endpoint is reachable. Access still fails because the cluster does not trust the caller identity.SecurityAdvanced20 minProSECURITY-1213Brute-force detection looks quietA login surface sits behind multiple proxies and the detection pipeline treats one forwarded header as authoritative.SecurityAdvanced20 minProSECURITY-066JWKS cache on the API gateway stays stale after OIDC signing key rotationThe identity provider is healthy and publishes the new key, but valid tokens still fail because the gateway never refreshed its cached trust material in time.SecurityAdvanced20 minProSECURITY-089SIEM suppression rule hides the second stage of an attackThe first alerts are known noise, but the actual compromise gets hidden because the suppression logic keys on a reused naming pattern across rebuilt hosts.SecurityAdvanced20 minPro