정보보안기사
753 incident response problems that help with 정보보안기사 prep.
먼저 읽을 가이드
추천 문제
All problems (753)
SECURITY-1198Cloud audit trail is complete in one account but gaps appearA multi-account logging design followed public cloud guidance. A permission change in one account now creates partial visibility loss that is easy to miss from the central console.SecurityAdvanced23 minProSECURITY-1195Cloud role assumption succeeds in one region and fails in anotherA cloud auth rollout followed community guidance and worked in one region. A second region fails because the trust condition still expects the previous audience or issuer pattern.SecurityAdvanced23 minProSECURITY-053CSP nonce is generated correctly but disappears after CDN template cachingThe application renders a fresh nonce, yet the browser still blocks the script because the cached edge fragment reuses a stale header-body combination.SecurityAdvanced23 minProSECURITY-090Vault unseal succeeds but one performance standby still serves stale auth configuration after leader failoverThe cluster looks healthy again, yet some login paths still fail because a standby node continues using old auth backend settings after control-plane leadership changed.SecurityAdvanced23 minProSECURITY-1207WAF blocks the obvious payload but a normalized path still reaches the backend through an alternate routeThe rule looks effective in one test, yet another path representation slips through because proxy and WAF normalize differently.SecurityAdvanced23 minProSECURITY-1205Client certificate rotation is healthy on the app tier but one gateway still trusts the previous intermediate onlyRotated client certs work through one path and fail through another because the gateway layer did not receive the same intermediate CA update as the application tier.SecurityAdvanced24 minProSECURITY-1181Internal registry trust breaksOperators rotate certificates after reading public advice, but only one served path is broken because it omits the intermediate chain.SecurityAdvanced24 minProSECURITY-051JWKS key rotation reaches the web tier but one API pod still caches the old signerLogin works on some paths, yet token validation fails intermittently because one long-lived process never refreshed the current signing keys.SecurityAdvanced24 minProSECURITY-1200mTLS breaks only on rotated clientsA certificate rollout follows community guidance and appears fine on servers. Client auth still fails on one path because not every validator tier received the new intermediate bundle.SecurityAdvanced24 minProSECURITY-069Organization-wide CloudTrail is enabled but one region never uses the expected KMS keyAudit logging exists everywhere, yet one region violates the encryption standard because replication and key policy assumptions drifted apart over time.SecurityAdvanced24 minProSECURITY-055EDR quarantine removes the log shipper binary and blinds central visibilityContainment works on the compromised host, but the action also stops telemetry collection and makes the rest of the investigation much harder.SecurityAdvanced25 minProSECURITY-040New allow rule never takes effectOperators add the expected allow rule for an update feed or admin flow, but traffic still fails because an earlier broader deny or different zone match wins first.SecurityAdvanced25 minProSECURITY-060GuardDuty member onboarding failsThe delegated admin path looks correct, but one child account never enables the detector because organizational guardrails deny the role creation needed by the service.SecurityAdvanced26 minProSECURITY-032KMS alias resolves correctly but decrypt still fails for the app roleThe application can discover the key alias and reach KMS, yet decrypt operations fail because the key policy and IAM policy do not grant the same effective path.SecurityAdvanced26 minProSECURITY-1187mTLS works on the primary route but fails during failoverA platform verified mTLS on the primary route only. Community discussions suggest the failover path often drifts, and now that path rejects client certs.SecurityAdvanced26 minProSECURITY-006Audit log volume drops after agent restart despite healthy daemon statusThe collector service looks healthy, but filtering or delivery state changes silently reduce security log coverage.SecurityAdvanced27 minProSECURITY-037Least-privilege refactor breaks cross-account accessA role assumption path worked before the permission cleanup, but third-party or cross-account access now fails because the new trust conditions no longer align with the expected external ID flow.SecurityAdvanced27 minProSECURITY-003WAF rule deployment blocks admin API but misses the real attack pathA hotfix rule stops valid management traffic while the malicious request pattern still finds an unprotected endpoint.SecurityAdvanced28 minProSECURITY-009Mutual TLS works on primary path but fails after east-west failoverCertificates and policies look valid, but the fallback service path presents a different trust context and breaks authentication.SecurityAdvanced29 minProSECURITY-1599A CrowdSec parser correction lands and one scenario still missesOne CrowdSec scenario still misses after parser corrections.SecurityIntermediate8 minPro