정보보안기사
753 incident response problems that help with 정보보안기사 prep.
먼저 읽을 가이드
추천 문제
All problems (753)
SECURITY-086Federated logout succeeds in the IdP but leaves the local admin session alive on the legacy appThe user appears signed out globally, but the legacy admin panel still accepts requests because its local session invalidation is not coupled to federation logout.SecurityIntermediate16 minFreeSECURITY-068MFA-enforced sudo flow breaks non-interactive automation on one hostThe stronger policy is correct for humans, but the service account path now fails because the exempt automation group was never applied consistently.SecurityIntermediate16 minFreeSECURITY-071OAuth login fails after a vanity-domain cutoverThe app and IdP are healthy, but authentication loops because the new branded callback path does not exactly match the registered redirect URI set.SecurityIntermediate16 minFreeSECURITY-192A parser becomes more correct while one detection silently depends on the old broken field shape during a failover rehearsalData quality improves and a rule built on yesterday's bug stops matching. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-288A parser normalization fix improves usernames while scheduled SIEM exports still query the old field shapes and emit empty reports during a failover rehearsalDashboards look healthy and nightly reporting continues living in the previous schema. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-240A telemetry parser lowercases usernames while one detection still depends on the old mixed-case service account form during a failover rehearsalThe data is normalized and one analytic still expects the previous representation. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-082TLS offload proxy re-encrypts with a deprecated cipher set and only one partner API rejects itClient-facing certificates look modern, but one partner integration breaks because the upstream re-encryption profile still uses a weaker legacy policy.SecurityIntermediate17 minFreeSECURITY-064WAF bot challenge protects the browser path but blocks webhook callbacks from non-browser clientsThe site is safer for humans, but an integration silently breaks because the challenged path now assumes browser behavior that the webhook sender never provides.SecurityIntermediate17 minFreeSECURITY-059Conditional access blocks the break-glass admin path during a device compliance incidentThe stronger policy makes sense normally, but the emergency access route now fails because it was never carved out from the same device compliance requirements.SecurityIntermediate18 minFreeSECURITY-073mTLS client authentication failsThe certificate is valid and trusted, but client auth still fails because the service enforces a SAN type that the issued cert never included.SecurityIntermediate18 minFreeSECURITY-067Certificate transparency alert points to a legacy SAN certificate still trusted by one proxy pathThe newly issued certificate is intentional, but one forgotten proxy still trusts the older SAN chain and continues to present the unexpected path.SecurityIntermediate19 minFreeSECURITY-010Password policy update breaks automation account loginA stronger policy is applied broadly, but one unattended account still uses the old credential pattern and starts failing.SecurityBeginner13 minFreeSECURITY-007Fail2ban blocks internal health checks after noisy auth failuresA brute-force defense rule works, but its source grouping catches internal monitoring traffic by mistake.SecurityBeginner15 minFreeSECURITY-270Browser isolation covers the main admin page while websocket upgrades to the same host bypass the isolated route during a failover rehearsalThe most visible path is protected and a less visible interactive path is not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-035Identity provider session expires before a long-running admin workflow finishesThe user signs in successfully and starts a privileged operation, but the background confirmation step fails because the IdP session duration is shorter than the workflow window.SecurityBeginner17 minFreeSECURITY-061SAML login fails after an IdP migrationThe IdP is reachable and the assertion is signed, but the application still rejects login because the expected identity field changed during the migration.SecurityIntermediate18 minFreeSECURITY-054SIEM parser timezone drift shifts the incident timeline by several hoursThe raw logs are present, but correlation and response decisions go wrong because one pipeline normalizes timestamps differently from the rest of the stack.SecurityIntermediate19 minFreeSECURITY-1617A mTLS policy is correct and one route still failsOne route still fails after an mTLS trust update.SecurityBeginner8 minFreeSECURITY-1687A SIEM allowlist is updated and one alert still firesAn alert still fires after the SIEM allowlist was updated.SecurityBeginner8 minFreeSECURITY-1697A SIEM allowlist is updated and one alert still firesAn alert still fires after the allowlist update.SecurityBeginner8 minFree