Certification753 problems· 15 reviewed

정보보안기사

753 incident response problems that help with 정보보안기사 prep.

All problems (753)

SECURITY-1260Password spray continues through rate limitingAn authentication edge still suffers password spraying even after strict per-IP limits were rolled out.SecurityIntermediate16 minProSECURITY-1274Secret scan alerts keep returningA team rotates and removes a credential from the primary repository and still sees recurring alerts tied to the same value.SecurityIntermediate16 minProSECURITY-1212Secret was revoked quickly but scanners keep firingA token leak is revoked and replaced promptly, but secret scanning continues to alert for days.SecurityIntermediate16 minProSECURITY-116Windows event forwarding over mutual auth works, but the subscription content format drops PowerShell script block logsThe channel is healthy, yet investigation quality degrades because the collector-side format setting strips fields one detection depends on.SecurityAdvanced16 minProSECURITY-142A break-glass account is excluded from conditional access, but the session lifetime policy still revokes it before the maintenance task finishesThe account bypasses the main gate, yet another identity control still constrains the operation.SecurityAdvanced17 minProSECURITY-155A DLP sensor classifies the document correctly, but a newly compressed archive format bypasses the extraction depth limit and the policy never sees the payloadContent controls are configured, yet packaging format changed the scanner's visibility boundary.SecurityAdvanced17 minProSECURITY-1291A JWKS rotation is complete but one consumer still failsA token issuer rotates keys and one consumer behind a proxy continues rejecting fresh tokens.SecurityAdvanced17 minProSECURITY-1289A JWT audience check passes in staging but fails in productionAuthentication works end-to-end in staging and fails only in production behind an API gateway performing token exchange or translation.SecurityAdvanced17 minProSECURITY-123A named location in conditional access misses the new SD-WAN egress IP range, and compliant users are suddenly blocked after failoverIdentity posture is good, but network identity changed underneath the access policy.SecurityAdvanced17 minProSECURITY-293A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a maintenance template changeThe chain is globally right and one trust consumer is still anchored to the past. The path looked healthy before the template changed, but one inherited assumption no longer matches the live environment.SecurityAdvanced17 minProSECURITY-297A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a retention policy refreshThe chain is globally right and one trust consumer is still anchored to the past. The operational object still exists somewhere in the system, but the lifecycle policy around its supporting state no longer matches reality.SecurityAdvanced17 minProSECURITY-295A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after an environment identity renameThe chain is globally right and one trust consumer is still anchored to the past. The functional path still exists, but one identity, namespace, or naming assumption still points at the previous environment contract.SecurityAdvanced17 minProSECURITY-1232A revoked credential still keeps surfacing in alertsAfter a credential rotation, scanners continue to alert because an old downloadable debug archive still contains generated metadata from the leak window.SecurityIntermediate17 minProSECURITY-1227A revoked token keeps triggering alertsSecret rotation is complete and scanners still report findings tied to historic debug bundles or retained CI artifacts.SecurityIntermediate17 minProSECURITY-1252A rotated secret keeps alertingAfter incident response, teams still see alerts tied to an older downloadable diagnostic bundle produced during the leak window.SecurityIntermediate17 minProSECURITY-1242A rotated secret keeps triggering alertsAn incident response team rotates a secret and later keeps seeing alerts tied to an old downloadable diagnostic archive.SecurityIntermediate17 minProSECURITY-1247A rotated secret keeps triggering alertsAfter a secret rotation, teams still see alerts tied to an old downloadable artifact generated during the incident window.SecurityIntermediate17 minProSECURITY-162A signed identity response is valid while one relying party rejects its audience string under different normalization rules during a failover rehearsalTrust succeeds cryptographically and string semantics still break the session. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced17 minProSECURITY-140An incident isolation rule cuts a host off from attackers and also from the EDR telemetry path, leaving responders blindContainment succeeds, yet investigation quality collapses because the rule removed the team's own visibility channel.SecurityAdvanced17 minProSECURITY-1281An OAuth callback succeeds on the identity provider but the app rejects the...An OAuth callback succeeds on the identity provider but the app rejects the... focuses on Identity And Access and asks the reader to isolate the key signal. OIDC callback bugs can be reverse-proxy identity bugs wearing an auth mask.SecurityAdvanced17 minPro