Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

All problems (753)

SECURITY-1433A JWKS rotation succeeds and one edge tier still rejects valid tokensA JWKS rotation succeeds and one edge tier still rejects valid tokens focuses on Cache Control and asks the reader to isolate the key signal in NGINX. JWKS cache issues can hide at the path level even when the issuer hostname is shared.SecurityAdvanced14 minProSECURITY-1443A JWKS rotation succeeds and one edge tier still rejects valid tokensOne application starts failing token validation after a key rotation while another under the same issuer still works.SecurityAdvanced14 minProSECURITY-1346A Netgate and CrowdSec style ban pipeline blocks the proxy addressA Netgate and CrowdSec style ban pipeline blocks the proxy address focuses on incident-response and asks the reader to isolate the key signal in NGINX. Source-IP based security automation breaks quickly when proxy trust boundaries...SecurityIntermediate14 minProSECURITY-1337A Prometheus alert route looks normal and a security incident still pages the...A Prometheus alert route looks normal and a security incident still pages... focuses on Deployment Governance and asks the reader to isolate the key signal in grafana. Routing errors in alerting often begin with label loss earlier in the p...SecurityAdvanced14 minProSECURITY-1389A remediation feed is healthy and one region ignores itA remediation feed is healthy and one region ignores it focuses on incident-response and asks the reader to isolate the key signal in Cloudflare. Security feed drift can come from edge cache key design, not from the upstream deci...SecurityAdvanced14 minProSECURITY-1429A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when apps only invalidate p...SecurityAdvanced14 minProSECURITY-1439A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when pools refresh on...SecurityAdvanced14 minProSECURITY-1449A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when pools refresh on...SecurityAdvanced14 minProSECURITY-1419A service binding receives a tighter policy and one application tier keeps...A service binding receives a tighter policy and one application tier keeps... focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can persist when applications couple reloads to secret change...SecurityAdvanced14 minProSECURITY-1409A service binding receives the correct policy on first rollout and later...A service binding receives the correct policy on first rollout and later... focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Permission drift can survive policy rollout when pooled connections cache earlie...SecurityAdvanced14 minProSECURITY-1322A Vault policy looks permissive and KV reads still failA service token is updated and later can enumerate secrets but cannot actually read the intended values from Vault.SecurityAdvanced14 minProSECURITY-1401An access proxy protects the user API and one newly split service path is...An access proxy protects the user API and one newly split service path is... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Security regressions often come from route shadowing, not from a mis...SecurityAdvanced14 minProSECURITY-1399An edge remediation list is updated and one POP still serves stale allow...An edge remediation list is updated and one POP still serves stale allow... focuses on incident-response and asks the reader to isolate the key signal in Cloudflare. Edge caching bugs can live in fetch path variants, not only in the visibl...SecurityAdvanced14 minProSECURITY-1416An egress-deny policy passes init checks and later leaks telemetryAn egress-deny policy passes init checks and later leaks telemetry focuses on network-policy and asks the reader to isolate the key signal in cilium. Mesh insertion can change the dataplane attachment point after early policy...SecurityAdvanced14 minProSECURITY-1426An egress-deny policy passes init checks and later leaks telemetryAn egress-deny policy passes init checks and later leaks telemetry focuses on network-policy and asks the reader to isolate the key signal in cilium. Service meshes can change the dataplane attachment point after init-time poli...SecurityAdvanced14 minProSECURITY-1436An egress-deny policy passes init checks and later leaks telemetryAn egress-deny policy passes init checks and later leaks telemetry focuses on network-policy and asks the reader to isolate the key signal in cilium. Service meshes can change dataplane attachment points after init-time policy checks h...SecurityAdvanced14 minProSECURITY-1446An egress-deny policy passes init checks and later leaks telemetryAn egress-deny policy passes init checks and later leaks telemetry focuses on network-policy and asks the reader to isolate the key signal in cilium. Service meshes can change dataplane attachment after init-time checks have already pa...SecurityAdvanced14 minProSECURITY-1406An init container validates egress against an allowlist and production still...An init container validates egress against an allowlist and production... focuses on network-policy and asks the reader to isolate the key signal in cilium. Security validation done too early in pod lifecycle can certify a network sta...SecurityAdvanced14 minProSECURITY-1384An NGINX allowlist protects private APIs and one upstream app becomes...An NGINX allowlist protects private APIs and one upstream app becomes... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Security gaps can live in the ordering between normalization and authorization, no...SecurityAdvanced14 minProSECURITY-1374An NGINX auth_request gateway protects normal methods and one CORS preflight...An NGINX auth_request gateway protects normal methods and one CORS... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Method-specific branches in proxies can bypass security logic even when the main path...SecurityAdvanced14 minPro