정보보안기사
753 incident response problems that help with 정보보안기사 prep.
먼저 읽을 가이드
추천 문제
All problems (753)
SECURITY-1444A hardened proxy protects the main admin route and an internal DAV alias still permits writesA proxy looks hardened and a legacy authoring endpoint still accepts writes through one alias path.SecurityAdvanced13 minProSECURITY-1434A hardened proxy protects the main admin route and an internal DAV alias...A hardened proxy protects the main admin route and an internal DAV alias... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can bypass expected auth when named locations do not inhe...SecurityAdvanced13 minProSECURITY-1404A hardened reverse proxy blocks all normal verbs and still leaks file...A hardened reverse proxy blocks all normal verbs and still leaks file... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Security gaps often hide in old HTTP methods that were never exercised during stan...SecurityAdvanced13 minProSECURITY-1328A private registry login is successful and image pulls still return 401A private registry login is successful and image pulls still return 401 focuses on Identity And Access and asks the reader to isolate the key signal in docker. Auth redirects across hosts can fail at cookie scope even when credentials and TLS are co...SecurityIntermediate13 minProSECURITY-1325A WAF managed rule blocks only one mobile clientA WAF ruleset update is followed by selective failures affecting only one legacy mobile client integration.SecurityIntermediate13 minProSECURITY-1394An NGINX auth_request flow protects GET and POST and one WebDAV verb bypasses...An NGINX auth_request flow protects GET and POST and one WebDAV verb... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Rare HTTP verbs often follow older location trees and can bypass newer auth subrequ...SecurityAdvanced13 minProSECURITY-1342An OpenSearch dashboard login loopsA proxy hardening change improves cookie posture and later dashboard users get trapped in a login redirect loop.SecurityIntermediate13 minProSECURITY-1338An OpenSearch Dashboards login loop appearsAn OpenSearch Dashboards login loop appears focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Modern cookie defaults can break older federated flows even when every credential and endpoint is correct.SecurityIntermediate13 minProSECURITY-1352An OpenSearch SSO redirect loop appears after proxy hardeningA reverse proxy is hardened and later users become trapped in a dashboard login loop even though the identity provider is healthy.SecurityIntermediate13 minProSECURITY-1316An SSH CA rollout signs host certificates correctly and engineers still get...An SSH CA rollout signs host certificates correctly and engineers still get... focuses on Identity And Access and asks the reader to isolate the key signal in Linux. SSH CA incidents often hide in stale host cert issuance rather t...SecurityIntermediate13 minProSECURITY-1396A Cilium egress deny policy appears tight and one init container still...A Cilium egress deny policy appears tight and one init container still... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Short-lived container phases can expose timing windows that st...SecurityAdvanced14 minProSECURITY-1367A Cilium FQDN policy allows the configured hostname and still blocks trafficA service mesh is enabled and only name-based egress policy begins failing for one dependency path.SecurityAdvanced14 minProSECURITY-1355A Cloudflare Access app is protected on 443 and an alternate admin port...A Cloudflare Access app is protected on 443 and an alternate admin port... focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cloudflare. Zero Trust at the main hostname does not automatically...SecurityAdvanced14 minProSECURITY-1391A Cloudflare Access application protects the dashboard and one API path stays...A Cloudflare Access application protects the dashboard and one API path... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Machine-auth exceptions can unintentionally shadow user-facing policy when hos...SecurityAdvanced14 minProSECURITY-1326A GitHub package publish from Dependabot failsA GitHub package publish from Dependabot fails focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Different GitHub event types can carry meaningfully different token capabilities even inside one repos...SecurityAdvanced14 minProSECURITY-1351A Grafana login succeeds and team access disappearsAn SSO schema update lands and later Grafana users can log in but lose the permissions tied to their old team claim mapping.SecurityAdvanced14 minProSECURITY-1361A Grafana SSO login succeeds and folders vanishAn IdP schema update rolls out and later Grafana users can log in but lose access to the teams and folders they previously owned.SecurityAdvanced14 minProSECURITY-1403A JWKS rotation finishes cleanly and token verification still fails on one...A JWKS rotation finishes cleanly and token verification still fails on one... focuses on Cache Control and asks the reader to isolate the key signal in NGINX. Key rotation failures often come from stale cache behavior, not from bad tokens...SecurityAdvanced14 minProSECURITY-1413A JWKS rotation succeeds and one edge still rejects valid tokensA JWKS rotation succeeds and one edge still rejects valid tokens focuses on Cache Control and asks the reader to isolate the key signal in NGINX. JWKS cache bugs can be path-scoped even when the issuer hostname is shared across applications.SecurityAdvanced14 minProSECURITY-1423A JWKS rotation succeeds and one edge tier still rejects valid tokensA JWKS rotation succeeds and one edge tier still rejects valid tokens focuses on Cache Control and asks the reader to isolate the key signal in NGINX. JWKS cache bugs can hide at the path level even when the issuer hostname is shared.SecurityAdvanced14 minPro