정보보안기사
753 incident response problems that help with 정보보안기사 prep.
먼저 읽을 가이드
추천 문제
All problems (753)
LINUX-097AppArmor profile loads but one helper binary escapes mediationPrimary commands are constrained, yet a helper path stays unrestricted because the profile pattern never matched the deployed binary location.LinuxAdvanced17 minProSECURITY-1271JWT verification fails after a planned key rotationAn OIDC issuer rotates signing keys and one downstream service alone begins rejecting valid tokens.SecurityAdvanced17 minProSECURITY-133Passwordless FIDO works on the web portal, but the legacy VPN RADIUS mapping still expects the old UPN suffix and rejects the sessionModern identity succeeds in one channel while a legacy gateway still anchors on an outdated identity format.SecurityAdvanced17 minProSECURITY-130SCIM soft-delete disables the account in the app, but a nested group from a secondary directory sync still grants access through another routeOffboarding looks complete in the primary system, yet effective authorization still arrives from a parallel identity feed.SecurityAdvanced17 minProSECURITY-1217Secret scanning catches the token againA revoked token disappears from the repo tree but scanning keeps flagging downloads or release bundles.SecurityIntermediate17 minProSECURITY-1204Temporary allowlist fixes a false positive but breaks the trust boundary by matching a broader source range than intendedA fast incident fix restores service, yet the allowlist rule now covers far more source space than the team originally intended to trust.SecurityIntermediate17 minProSECURITY-1199Temporary exception in the WAF lives foreverA public WAF tuning pattern recommends a quick allow rule. The exception fixes the incident, then quietly becomes part of the long-term exposure surface.SecurityIntermediate17 minProSECURITY-312A browser isolation or proxy layer protects the main UI while websocket or export paths bypass the protected route entirely during a failover rehearsalThe most visible path is controlled and a lower-visibility path still leaks data or interactivity. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-119A CASB session rule blocks downloads in the browser, but the desktop client uses a direct API token path that bypasses the web controlThe browser looks governed, yet data still leaves the tenant because another client channel was never put behind the same session controls.SecurityAdvanced18 minProSECURITY-222A conditional access policy requires compliant devices while cross-tenant claims are minted by the wrong tenant context during a failover rehearsalThe rule is correct in principle and one federated identity path never carries the expected compliance signal. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-1241A login loop persists after a successful OIDC callbackOne hostname or browser completes the login flow while another loops indefinitely even though the provider logs show success.SecurityAdvanced18 minProSECURITY-296A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a control-plane upgradeThe chain is globally right and one trust consumer is still anchored to the past. The workload or policy had been stable, but the upgraded control layer now interprets one dependency differently.SecurityAdvanced18 minProSECURITY-294A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service during a failover rehearsalThe chain is globally right and one trust consumer is still anchored to the past. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-298A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service during a rollback rehearsalThe chain is globally right and one trust consumer is still anchored to the past. The steady path hides the problem until the system is asked to move backward through the dependency chain.SecurityAdvanced18 minProSECURITY-153A PKI automation job renews the leaf certificate first, but the pinned intermediate bundle on one appliance is refreshed only the next day and outbound trust breaks overnightThe chain is valid globally, yet one dependent appliance still pins the previous chain layout.SecurityAdvanced18 minProSECURITY-113A renewed intermediate certificate is deployed, but the CRL distribution point still serves the expired issuer chainThe visible cert chain looks modern, yet some clients reject it because revocation infrastructure still references the old issuing hierarchy.SecurityAdvanced18 minProSECURITY-469A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate18 minProSECURITY-264A Vault policy grants transit encryption while the wrapped response workflow strips the unwrap capability from operators during a failover rehearsalThe crypto permission exists and the operational path to use it is incomplete. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-276An incident quarantine revokes general egress while forensic collection still depends on one artifact upload endpoint during a failover rehearsalContainment is immediate and visibility disappears with it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-1246An OIDC login loop continues after a successful callbackOne hostname or browser completes the sign-in flow and another loops forever even though the provider logs a successful callback.SecurityAdvanced18 minPro