Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1555A browser isolation connector updates and one download still exits unsandboxedArchive downloads bypass browser isolation after connector updates.SecurityAdvanced11 minProSECURITY-1463A Cloudflare Access mTLS rule works in staging and fails in prodService auth works in staging cert profiles and breaks in production profiles that preserve SPIFFE casing.SecurityAdvanced11 minProSECURITY-1553A WAF managed rule exception is removed and one API still passes malicious payloadsMalicious payloads pass only on one hostname after managed rule cleanup.SecurityAdvanced11 minProSECURITY-1561An Elastic transform is corrected and one rule still misses hitsOnly one index family stops matching time-based detections after transform fixes.SecurityAdvanced11 minProSECURITY-1570An mTLS SPIFFE bundle narrows and one sidecar still trusts the old domainOne sidecar still trusts the old domain after SPIFFE bundle narrowing.SecurityAdvanced11 minProSECURITY-1567An OpenSearch rollover policy is fixed and one restored index still exposes historical dataOne restored index becomes public again after rollover policy cleanup.SecurityAdvanced11 minProSECURITY-1557An OpenSearch snapshot repository is secured and one restore still exposes historical documentsHistorical data becomes visible again only after snapshot restore.SecurityAdvanced11 minProSECURITY-1451A branch office device flow rate limiter starts starving legitimate usersDevice login starts failing only from one branch after kiosks and staff moved behind the same NAT path.SecurityAdvanced12 minProSECURITY-1499A browser isolation policy is enabled and downloads still bypass scanningBrowser isolation works, but downloads bypass malware scanning after a connector topology change.SecurityAdvanced12 minProSECURITY-1509A browser isolation policy is enabled and downloads still bypass scanningBrowser isolation works, but downloads bypass malware scanning after a connector topology change.SecurityAdvanced12 minProSECURITY-1529A browser isolation policy is enabled and downloads still bypass scanningBrowser isolation works, but downloads bypass scanning after connector topology change.SecurityAdvanced12 minProSECURITY-1558A certificate pin set is refreshed and one mobile API still breaksOnly resumed mobile sessions fail certificate pinning after a chain refresh.SecurityAdvanced12 minProSECURITY-1460A machine identity rotates and pooled outbound TLS sessions keep failingA machine identity rotates and pooled outbound TLS sessions keep failing focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Credential rotation can fail in connection pools that treat TLS session state as...SecurityAdvanced12 minProSECURITY-1489A Vault agent rotates a certificate and the app still presents the old oneCertificate rotation succeeds in Vault and the application keeps serving the previous certificate until restart.SecurityAdvanced12 minProSECURITY-1551An Elastic detection rule is updated and one index set still misses alertsAlerts disappear only for one log family after detection rule updates.SecurityAdvanced12 minProSECURITY-1490An Envoy mTLS path validates new CRLs and one cluster still accepts revoked certsRevoked certificates continue to pass on one cluster after CRL rotation while others reject them correctly.SecurityAdvanced12 minProSECURITY-1500An mTLS allowlist updates and one service still trusts the retired client CAOne service continues trusting a retired client CA after an mTLS allowlist rotation.SecurityAdvanced12 minProSECURITY-1510An mTLS allowlist updates and one service still trusts the retired client CAOne service continues trusting a retired client CA after allowlist rotation.SecurityAdvanced12 minProSECURITY-1520An mTLS allowlist updates and one service still trusts the retired client CAOne service continues trusting a retired client CA after allowlist rotation.SecurityAdvanced12 minProSECURITY-1530An mTLS allowlist updates and one service still trusts the retired client CAOne service still trusts a retired client CA after allowlist rotation.SecurityAdvanced12 minPro