Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

All problems (753)

SECURITY-1335An Ubuntu unattended upgrade secures packages and leaves one bastion inaccessibleA hardened bastion receives unattended upgrades and later downstream systems that pin host identity stop trusting it.SecurityIntermediate14 minProSECURITY-1375Cloudflare Access protects the main hostname and an alternate admin listener...Cloudflare Access protects the main hostname and an alternate admin... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Edge access controls are only as complete as the hos...SecurityAdvanced14 minProSECURITY-1379Unattended upgrades complete and the host loses trust in its own workload...Unattended upgrades complete and the host loses trust in its own workload... focuses on Identity And Access and asks the reader to isolate the key signal in ubuntu. Automatic certificate renewal can break local trust pin...SecurityAdvanced14 minProSECURITY-1302Vault KV access works in the UI and fails in automationOperators validate access in the UI and later the service account still gets permission denied on KV reads.SecurityIntermediate14 minProSECURITY-1290A CSP rollout looks correct but one payment popup failsA security hardening rollout passes smoke tests and a third-party popup or embedded checkout later breaks in production.SecurityIntermediate15 minProSECURITY-1298A CSP update allows the vendor script but still breaks checkoutA CSP hardening rollout appears safe and one payment or verification flow still fails in production.SecurityIntermediate15 minProSECURITY-1292A SameSite fix solves desktop login and still breaks mobile webview SSOAn auth hardening change appears successful until mobile app login starts looping while desktop login remains normal.SecurityIntermediate15 minProSECURITY-1272A SameSite hardening change breaks SSO only on one browser flowA cookie hardening rollout leaves some browsers or embedded login flows broken while ordinary browser login still succeeds.SecurityIntermediate15 minProSECURITY-1282A secret rotation completes in the vault but one service still leaks the old valueA secret is rotated centrally and one service alone continues authenticating with the old value despite a documented hot-reload endpoint.SecurityIntermediate15 minProSECURITY-1300A signed download URL validates in staging but fails in productionSigned file links work in staging and fail only behind the production proxy or CDN path.SecurityIntermediate15 minProSECURITY-1288A signed URL looks valid but file downloads still failDownloads begin failing only after a reverse-proxy or CDN change, even though the signed URL generator code did not change.SecurityIntermediate15 minProSECURITY-1278An app trusts X-Forwarded-Proto from one proxy hop and starts misclassifying secure requestsA reverse proxy or CDN is inserted ahead of an existing app and secure redirect or cookie behavior becomes inconsistent.SecurityIntermediate15 minProSECURITY-134A CASB inline proxy rewrites the downloaded filename, and the DLP hash allowlist no longer matches the approved documentContent is safe, yet the downstream control no longer recognizes it because one enforcement layer changed the file artifact identity.SecurityAdvanced16 minProSECURITY-1284A new WAF rule blocks only file uploadsA WAF tuning change appears safe until one upload-heavy path begins failing only after a CDN or edge normalization update.SecurityIntermediate16 minProSECURITY-1287A rate limiter reduces abuse in IPv4 logs but an attacker keeps spraying via IPv6 privacy addressesPer-IP rate limiting appears to work and an attack still continues from an address family the dashboards underweight.SecurityAdvanced16 minProSECURITY-1267A SameSite cookie setting breaks SSO only on one browser pathA browser-specific SSO failure appears after cookie hardening, while the same app still works through simpler redirect paths.SecurityIntermediate16 minProSECURITY-141A SAML assertion signs correctly, but the audience URI casing changed during the domain move and one service provider rejects only mixed-case callbacksIdentity proof is valid, yet string normalization assumptions differ between the two ends.SecurityAdvanced16 minProSECURITY-1257A secret is rotated but alerts keep firingA team revokes a credential and still sees recurring detections tied to the same historical leak window.SecurityIntermediate16 minProSECURITY-1269A secret leak alert keeps returningA credential is rotated and removed from the main repo, but scanning alerts keep resurfacing from related automation surfaces.SecurityIntermediate16 minProSECURITY-351A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate16 minPro