Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

All problems (753)

SECURITY-100Vault seal migration completes on the leader but one standby still advertises stale recovery key requirementsThe cluster seems healthy, yet operational confusion persists because one standby node still reflects the previous seal-state assumptions after migration.SecurityAdvanced20 minProLINUX-079auditd backlog overflow drops the exact events needed to explain the breach windowAuditing is enabled, yet the highest-value records are missing because the kernel backlog overflowed during bursty activity and the team never noticed the loss signal.LinuxAdvanced21 minProSECURITY-1193Cloud audit agent looks healthy but stopped shipping logs after a service-account rotationThe agent process runs, yet the audit pipeline is effectively dark because the credential or permission path it uses no longer matches the rotated identity.SecurityAdvanced21 minProSECURITY-080Endpoint isolation policy blocks the EDR cloud callback and the host never recovers from containmentContainment starts correctly, but the host stays permanently isolated because the policy also cut off the control channel required to release it safely.SecurityAdvanced21 minProSECURITY-1211Federated login breaks only on callbackAn OIDC flow still reaches the provider successfully, but the callback handler rejects the return due to missing browser state.SecurityAdvanced21 minProSECURITY-1189IAM role rotation looks complete but long-lived pods keep using stale credentialsA cloud role was rotated and policy updated, yet running workloads continue to fail or over-permit because old credentials remain cached in process state.SecurityAdvanced21 minProSECURITY-062SIEM correlation deduplicates brute-force alerts and hides the real spray scopeAnalysts see only a few incidents, but the attack is much wider because the correlation rule collapses repeated signals into one coarse event group.SecurityAdvanced21 minProSECURITY-084WAF JSON parser normalizes the body differently from the application and bypasses the intended block ruleSecurity rules appear present, but a crafted request still reaches the app because the protection layer interprets the JSON structure differently from the backend.SecurityAdvanced21 minProSECURITY-075An SCP allows the recovery service but blocks the dependent KMS decrypt call during restoreThe incident playbook launches correctly, but restore still fails because the organization policy forgot the downstream KMS permission the service actually needs.SecurityAdvanced22 minProSECURITY-057Certificate pinning fails only on the guest network after SSL inspection is enabledThe app works on trusted networks, but mobile users on the guest path fail because the intercepted certificate no longer matches the pinned expectation.SecurityAdvanced22 minProSECURITY-087CloudTrail organization trail exists but one delegated admin account writes to an unmonitored bucket in another regionAudit coverage seems complete, yet one privileged path is effectively invisible because the delegated admin is using a destination outside the monitored collection pattern.SecurityAdvanced22 minProSECURITY-070EDR quarantine removes the log shipper binary and host visibility disappears without an alertThe endpoint agent did its job from one perspective, but security operations lose telemetry because the quarantined component was also the only path to central visibility.SecurityAdvanced22 minProSECURITY-031IAM role trust policy rejects GitHub OIDC tokenThe workflow reaches the cloud provider, but the trust policy denies the token because the expected audience or subject does not match the actual issuer claims.SecurityIntermediate22 minProSECURITY-1210mTLS rotation looks complete but one gateway still failsAn mTLS rotation completes and most gateways recover, but one still rejects peers because its chain trust is incomplete.SecurityAdvanced22 minProSECURITY-1201OIDC issuer update looks complete but one validator still pins the old issuer URLMost auth flows recover after an issuer migration, yet one proxy or sidecar still rejects tokens because it continues to trust the previous issuer location.SecurityAdvanced22 minProSECURITY-1184OIDC login callback breaks behind proxyCommunity fixes focus on the identity provider, but the real break is that the edge proxy is building the wrong callback URL.SecurityAdvanced22 minProSECURITY-065Vault periodic token stops renewingThe workload starts normally, but long-lived sessions fail hours later because the renewal path assumed a parent-child token chain that no longer exists.SecurityAdvanced22 minProSECURITY-1191WAF allows the obvious route but still misses the attackA WAF rollout follows public guidance and appears healthy. Later, testing shows the same app is still reachable through an alternate hostname that bypasses the protected edge path.SecurityAdvanced22 minProSECURITY-1183AWS WAF blocks a safe admin pathA team enabled an AWS managed rule set following public guidance. An internal admin path now breaks because its request pattern trips a generic rule.SecurityAdvanced23 minProSECURITY-1203Central log pipeline is green but one parser update silently drops a whole class of security eventsCollection is alive and dashboards look healthy, yet one format change causes a parser to reject or discard a subset of events without obvious pipeline failure.SecurityAdvanced23 minPro