정보보안기사
753 incident response problems that help with 정보보안기사 prep.
먼저 읽을 가이드
추천 문제
All problems (753)
SECURITY-1427A fail2ban jail reads failures and stops banning correctlyA fail2ban jail reads failures and stops banning correctly focuses on abuse-protection and asks the reader to isolate the key signal in ubuntu. Structured log migrations can change which IP a parser captures even when the event itself i...SecurityIntermediate10 minProSECURITY-1417A fail2ban jail reads login failures correctly and stops banningA fail2ban jail reads login failures correctly and stops banning focuses on abuse-protection and asks the reader to isolate the key signal in ubuntu. Structured logging migrations can preserve the event and still change which IP field the...SecurityIntermediate10 minProSECURITY-1437A fail2ban jail still reads failures and stops banning correctlyAbuse spikes continue while fail2ban reports bans against the proxy after a move to structured logs.SecurityIntermediate10 minProSECURITY-1387A fail2ban rule triggers on the right log lines and never blocks the clientA fail2ban rule triggers on the right log lines and never blocks the client focuses on incident-response and asks the reader to isolate the key signal in Linux. Detection and enforcement can drift apart when one consumes par...SecurityIntermediate10 minProSECURITY-1568A PAM radius failover recovers and one host still rejects valid usersOne host rejects valid users only on radius failover paths.SecurityAdvanced10 minProSECURITY-1512A WAF exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON route family.SecurityIntermediate10 minProSECURITY-1522A WAF exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON route family.SecurityIntermediate10 minProSECURITY-1492A WAF managed rule exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON-heavy endpoint family.SecurityIntermediate10 minProSECURITY-1502A WAF managed rule exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON-heavy endpoint family.SecurityIntermediate10 minProSECURITY-1464An Elastic detection rule duplicates incidentsIncident count doubles after an ingest pipeline migration even though raw event volume is flat.SecurityIntermediate10 minProSECURITY-1474An Elastic detection stays noisyAlert volume rises after one ingest branch is normalized to ECS while another still uses pre-ECS field mapping.SecurityIntermediate10 minProSECURITY-1459An Elastic rule starts duplicating incidentsIncident count spikes after an ECS cleanup even though the underlying event volume did not change.SecurityIntermediate10 minProSECURITY-1415An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload bugs often come from inode and watcher semantics rather...SecurityIntermediate10 minProSECURITY-1425An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload problems are often inode or watcher issues, not stale data issues.SecurityIntermediate10 minProSECURITY-1435An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload bugs are often inode or watcher issues, not stale data issues.SecurityIntermediate10 minProSECURITY-1445An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload bugs are often inode or watcher issues, not stale content.SecurityIntermediate10 minProSECURITY-1473A Cloudflare Access policy allows service tokens and still blocks one routeService-token access works for normal paths and fails only when an upstream sends duplicated slashes.SecurityAdvanced11 minProSECURITY-1495A CrowdSec bouncer loads the new decision list and one reverse proxy still blocks healthy clientsHealthy clients remain blocked after CrowdSec decisions are cleaned up behind a reverse proxy chain refactor.SecurityAdvanced11 minProSECURITY-1505A CrowdSec decision list updates and healthy clients still blockHealthy clients remain blocked after decision cleanup behind a reverse proxy chain refactor.SecurityAdvanced11 minProSECURITY-1515A CrowdSec decision list updates and healthy clients still blockHealthy clients remain blocked after decision cleanup behind a reverse proxy chain refactor.SecurityAdvanced11 minPro