Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

LINUX-063sudoers include file is ignoredThe rule is written correctly, yet sudo behavior never changes because the included file fails the safety checks and is silently skipped.ReviewedLinuxBeginner13 minFreeLINUX-096NTP is synchronized but the hardware clock drifts back after every reboot and breaks certificatesThe running host time looks correct, but restarts reintroduce skew because the persistent hardware clock was never aligned.ReviewedLinuxIntermediate14 minFreeLINUX-481A sudo rule allows the target subcommand (Permission Denied)A sudo rule allows the target subcommand (Permission Denied) focuses on linux-identity-and-access and asks the reader to isolate Permission Denied. 실무에서는 linux-identity-and-access 문제를 볼 때 서비스 로그만 보지 말고 inode, 파일시스템 여유, 포트 점유, systemd 상태, 최근 패키지 변경까지 같이 확인해야 원인을 빨리 좁힐 수 있습니다.ReviewedLinuxIntermediate17 minProNETWORK-009An SNI routing problem where the TLS handshake fails only on certain domainsA situation where the certificate is valid but SNI routing is wrong, so only some domains fail.ReviewedNetworkAdvanced24 minProSECURITY-001The SSH management path is blocked after an overly narrow allowlist changeA situation where the access-control policy looks correct, but one jump-host range is missing, so the actual operations management path is blocked.ReviewedSecurityBeginner16 minFreeSECURITY-005IAM role rotation leaves one batch worker using stale credentialsMost services refresh correctly, but one worker process keeps using cached credentials and starts failing scheduled jobs.ReviewedSecurityIntermediate20 minPro

All problems (911)

NET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warningNET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warning is a hands-on troubleshooting drill. Check the certificate's expiry date against the current time. TLS and Certificate Chain needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedSecurityBeginner3 minFreeCORS error: No 'Access-Control-Allow-Origin' header is presentCORS error: No 'Access-Control-Allow-Origin' header is present is a hands-on troubleshooting drill. Read the most common CORS error and decide which side has to change. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, and the current live signal b...ReviewedSecurityBeginner3 minFree403 Forbidden: login works but one admin action is refused (vs 401)403 Forbidden: login works but one admin action is refused (vs 401) is a hands-on troubleshooting drill. Tell authentication failures (401) from authorization failures (403). Identity And Access needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedSecurityBeginner3 minFreeWARNING: UNPROTECTED PRIVATE KEY FILE: SSH refused on a new laptopWARNING: UNPROTECTED PRIVATE KEY FILE: SSH refused on a new laptop is a hands-on troubleshooting drill. Understand why ssh ignores a private key whose permissions are too open. Identity And Access needs to be checked by narrowing scope, recent change, and the current live sign...ReviewedSecurityBeginner3 minFreejwt expired (401): every request fails after about an hour in the appjwt expired (401): every request fails (Auth and Session Failure) is a hands-on troubleshooting drill. Recognise token expiry and the missing refresh step. token-validation needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서...ReviewedSecurityBeginner3 minFreeMixed Content: a chat widget disappears after switching to HTTPSMixed Content: a chat widget disappears (WAF and AppSec Controls) is a hands-on troubleshooting drill. Recognise mixed-content blocking. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 operationa...ReviewedSecurityBeginner3 minFreeSECURITY-033Managed WAF rule blocks a legitimate JSON admin requestThe API works for most clients, but a large or nested admin payload trips a managed protection rule and looks like an application bug at first glance.ReviewedSecurityIntermediate20 minFreeSECURITY-058OAuth device code session remains active after user offboardingThe user account is disabled, but a previously authorized device code flow keeps working because token revocation and downstream session invalidation were not linked tightly enough.ReviewedSecurityIntermediate20 minFreeSECURITY-056Secrets Manager rotation updates the writer credential but read replicas still use the old secretRotation completes successfully on the primary path, yet one read-side workload keeps failing because its secret retrieval or cache path was never included in the rotation design.ReviewedSecurityIntermediate21 minFreeSECURITY-034TLS renewal updates the leaf certificate but leaves the intermediate chain staleModern browsers appear fine on one path, yet API clients and internal services fail because the server still presents an incomplete chain after renewal.ReviewedSecurityIntermediate21 minFreeLINUX-096NTP is synchronized but the hardware clock drifts back after every reboot and breaks certificatesThe running host time looks correct, but restarts reintroduce skew because the persistent hardware clock was never aligned.ReviewedLinuxIntermediate14 minFreeSECURITY-001The SSH management path is blocked after an overly narrow allowlist changeA situation where the access-control policy looks correct, but one jump-host range is missing, so the actual operations management path is blocked.ReviewedSecurityBeginner16 minFreeSECURITY-025Locked-down file permission hides SSH authorized_keys from user sessionLocked-down file permission hides SSH authorized_keys from user session is a hands-on troubleshooting drill. The authorized key exists, but the home directory ownership or mode makes the SSH daemon ignore it. Identity and Access Management needs to be checked by narrowing scop...ReviewedSecurityBeginner14 minFreeLINUX-063sudoers include file is ignoredThe rule is written correctly, yet sudo behavior never changes because the included file fails the safety checks and is silently skipped.ReviewedLinuxBeginner13 minFreeSECURITY-016MFA enforcement skipped for legacy admin endpointMFA enforcement skipped for legacy admin endpoint is a hands-on troubleshooting drill. The main login path correctly enforces MFA, but a secondary admin route still accepts a weaker path. Identity and Access Management needs to be checked by narrowing scope, recent change, and...ReviewedSecurityBeginner14 minFreeSECURITY-1611A login page is correct and one callback still failsOne OAuth callback still fails after moving to a new subdomain.ReviewedSecurityBeginner6 minFreeSECURITY-1614A certificate is rotated and one client still rejects itOne client still rejects a rotated certificate.ReviewedSecurityBeginner7 minFreeSECURITY-1615A JWT issuer is updated and one verifier still rejects tokensOne verifier still rejects tokens after issuer cleanup.ReviewedSecurityBeginner7 minFreeSECURITY-1613A WAF rule is relaxed and one API call still gets 403One API call still gets 403 after relaxing a WAF rule.ReviewedSecurityBeginner7 minFreeAn AWS access key was pushed to a public GitHub repositoryAn AWS access key was pushed to a public GitHub repository is a hands-on troubleshooting drill. Respond to a leaked cloud credential in the right order: revoke first, investigate, then clean up history. AWS Incident Response Operations needs to be checked by narrowing scope, r...ReviewedSecurityIntermediate18 minFree