Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

All problems (753)

SECURITY-1382A Grafana auth proxy setup works and admin privileges disappearA Grafana auth proxy setup works and admin privileges disappear focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity regressions can come from harmless-looking canonicalization changes like lowercasing...SecurityIntermediate11 minProSECURITY-1392A Grafana team sync still works and one admin loses elevated accessA Grafana team sync still works and one admin loses elevated access focuses on Identity And Access and asks the reader to isolate the key signal in grafana. SSO regressions often come from type changes in claims, not just from missing values.SecurityIntermediate11 minProSECURITY-1488A JWKS rotation completes and one edge still serves stale keysSome clients validate new JWTs while one edge location keeps serving the old compressed JWKS.SecurityAdvanced11 minProSECURITY-1497A JWT issuer rotates keys and one gateway still rejects tokensOne gateway keeps rejecting new JWTs after key rotation while others recover immediately.SecurityAdvanced11 minProSECURITY-1507A JWT issuer rotates keys and one gateway still rejects tokensOne gateway keeps rejecting new JWTs after key rotation while others recover immediately.SecurityAdvanced11 minProSECURITY-1485A Palo Alto URL filtering update is synced and QUIC traffic still bypassesSafe browsing policy works for HTTPS and not for QUIC after an App-ID update.SecurityAdvanced11 minProSECURITY-1385A Prometheus exporter secret is rotated and alerting still uses the old...A Prometheus exporter secret is rotated and alerting still uses the old... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Hot-reload automation can succeed technically while watching the...SecurityIntermediate11 minProSECURITY-1493A Vault token revocation succeeds and an app still authenticatesAn application keeps renewing secrets briefly after its Vault parent token was revoked during an incident response action.SecurityAdvanced11 minProSECURITY-1503A Vault token revocation succeeds and the app still authenticatesAn application keeps renewing secrets briefly after its Vault parent token was revoked.SecurityAdvanced11 minProSECURITY-1513A Vault token revocation succeeds and the app still authenticatesAn application keeps renewing secrets briefly after its Vault parent token is revoked.SecurityAdvanced11 minProSECURITY-1523A Vault token revocation succeeds and the app still authenticatesAn application keeps renewing secrets briefly after Vault revocation.SecurityAdvanced11 minProSECURITY-1405An htpasswd secret is updated and the ingress still accepts the old passwordAn htpasswd secret is updated and the ingress still accepts the old password focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload problems can come from normalization logic in th...SecurityIntermediate11 minProSECURITY-1366A ban pipeline targets the proxy instead of the attackerA reverse proxy is inserted or reconfigured and automated bans later start punishing the proxy instead of abusive clients.SecurityIntermediate12 minProSECURITY-1454A Cloudflare Access service token works for normal API calls and fails on one...A Cloudflare Access service token works for normal API calls and fails on... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Upgrade paths often use different rule branches than ordinary HTTP re...SecurityAdvanced12 minProSECURITY-1469A JWKS rotation succeeds and one edge cache still serves the old key setSome clients validate new JWTs while one region keeps seeing the old JWKS after rotation.SecurityAdvanced12 minProSECURITY-1479A JWKS rotation succeeds and one edge still serves stale keysSome clients validate new JWTs while one edge path keeps serving the old compressed JWKS document.SecurityAdvanced12 minProSECURITY-1481A Keycloak login works and one app still loopsOIDC login loops only for one app after proxy host rewrites were centralized.SecurityAdvanced12 minProSECURITY-1480A secret rotation succeeds and RDS auth still failsDatabase logins fail intermittently after secrets rotation while some requests still succeed on long-lived workers.SecurityAdvanced12 minProSECURITY-1470A secrets rotation completes and database auth still failsDatabase auth fails intermittently after a secrets rotation while some workers continue to function.SecurityAdvanced12 minProSECURITY-1461A Vault Agent rotates the certificate and one JVM still presents the old chainAn mTLS client keeps presenting the retired chain after Vault Agent rotates the file-backed certificate.SecurityAdvanced12 minPro