정보보안기사
753 incident response problems that help with 정보보안기사 prep.
먼저 읽을 가이드
추천 문제
All problems (753)
SECURITY-1251An OIDC login loop persists after a successful callbackOne browser or hostname signs in successfully while another loops forever even though the provider logs show success.SecurityAdvanced18 minProSECURITY-1208Emergency allowlist fixes the outage but quietly leaves a much broader bypass than intendedA temporary rule restores access, yet it also permits traffic far outside the original blast radius because the exception is too broad.SecurityIntermediate18 minProSECURITY-1220Login throttling seems effective but API tokens still bypass itAn app reduces password spray on the browser login page but still sees abusive token requests continue unabated.SecurityIntermediate18 minProSECURITY-1225Login throttling works on the web form but API tokens still bypass itBrowser password spray drops quickly, but token-bearing API abuse continues through another path.SecurityIntermediate18 minProSECURITY-1256OIDC login succeeds at the provider but loops at the appOne login URL works while another hostname for the same app loops forever despite identical provider-side configuration.SecurityAdvanced18 minProSECURITY-1226OIDC login works in one browser but fails in anotherA login flow appears healthy in one hostname path or browser and fails with state or nonce errors in another.SecurityAdvanced18 minProSECURITY-101SAML audience matches, but ACS URL normalization drops the trailing slash and the login flow loops between the app and IdPAuthentication succeeds at the identity provider, yet the application rejects the response because the callback URL comparison is stricter than the team expected.SecurityAdvanced18 minProSECURITY-1202Scanner still sees an exposed admin routeA reverse-proxy rule from community examples protects the obvious admin path. Scanning still finds exposure because a normalized variant resolves through another rule path.SecurityIntermediate18 minProSECURITY-1186Secrets scanner flags a revoked key and the team cannot tell if the exposure is still realA pipeline finds a leaked credential pattern, but responders must determine whether the secret is active, historical, or already revoked before escalating incorrectly.SecurityIntermediate18 minProSECURITY-1197Security scan reports a public admin routeA route looks protected in manual testing, yet a scan still reaches the admin path because one redirect or normalized path bypasses the auth requirement.SecurityIntermediate18 minProSECURITY-126Vault dynamic database credentials expire before a long-running transaction completes, and the application reports random commit failuresSecrets are rotated safely, but workload runtime exceeds the lease model the security design assumed.SecurityAdvanced18 minProSECURITY-1194Basic auth on one route hides that the file-upload path uses a different location blockThe visible admin page is protected, but the upload path still reaches the backend unauthenticated because it matches another location rule.SecurityIntermediate19 minProSECURITY-336Containment revokes general egress while one evidence collection or telemetry upload endpoint was still needed for the investigation during a failover rehearsalThe isolation step works and responders lose the path that would have made the incident explainable. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced19 minProSECURITY-1182Fail2ban blocks trusted health checksA public Fail2ban recipe is copied into a reverse-proxy deployment and legitimate checks start getting banned as if they were attacks.SecurityIntermediate19 minProSECURITY-1190Scanner reports the upload path is openA basic-auth recipe from community forums was added to NGINX. The visible admin UI is protected, but an adjacent upload path still reaches the backend unauthenticated.SecurityIntermediate19 minProSECURITY-008Secrets scanner flags a rotated key that is already revokedThe alert is technically correct for the repository history, but the key is no longer active and the response path is unclear.SecurityIntermediate19 minProSECURITY-1209SIEM pipeline is healthy but one event class disappearsA forwarder still ships logs, but investigation data is missing because a parser drops one event type after a field change.SecurityIntermediate19 minProSECURITY-589A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate20 minProSECURITY-649A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate21 minProSECURITY-1206JWT validation fails after key rotationA signing key rotation succeeds for most services but one verifier keeps rejecting valid tokens.SecurityAdvanced21 minPro