CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-1560An mTLS service policy is narrowed and one sidecar still trusts the retired client bundleOne sidecar still trusts retired clients after narrowing mTLS policy.SecurityAdvanced12 minProSECURITY-1418A high-severity Elastic SIEM rule goes quietA high-severity Elastic SIEM rule goes quiet focuses on schema-migration and asks the reader to isolate the key signal in elastic. Field names surviving a migration do not guarantee their meanings stayed identical for detection logic.SecurityAdvanced13 minProSECURITY-1458A load balancer failover keeps client cert auth green and later breaks itA load balancer failover keeps client cert auth green and later breaks it focuses on redundancy and asks the reader to isolate the key signal in palo-alto. Failover breaks in certificate auth can hide in responder cache state rather than...SecurityAdvanced13 minProSECURITY-1408A SIEM rule meant to catch admin abuse goes quietA SIEM rule meant to catch admin abuse goes quiet focuses on schema-migration and asks the reader to isolate the key signal in elastic. Detection rules often fail after schema migrations because the underlying events are present under new fi...SecurityAdvanced13 minProSECURITY-1398An Elastic detection rule misses admin abuseAn Elastic detection rule misses admin abuse focuses on incident-response and asks the reader to isolate the key signal in Opensearch. Detection quality can degrade when schema evolution changes relationships between actor and target fie...SecurityAdvanced13 minProSECURITY-1388An Elastic detection rule still misses one attacker pathAn Elastic detection rule still misses one attacker path focuses on incident-response and asks the reader to isolate the key signal in Opensearch. Detection drift often follows schema normalization changes rather than event loss.SecurityAdvanced13 minProSECURITY-1448An Elastic SIEM rule goes quietIngest is healthy and one critical admin-abuse rule silently stops firing after an ECS migration.SecurityAdvanced13 minProSECURITY-1438An Elastic SIEM rule goes quiet (siem-correlation-followed-legacy-field-after-semantic-drift)An Elastic SIEM rule goes quiet (siem-correlation-followed-legacy-field-after... focuses on schema-migration and asks the reader to isolate the key signal in elastic. Schema migrations can preserve field names while changing what th...SecurityAdvanced13 minProSECURITY-1428An Elastic SIEM rule goes quiet (siem-rule-followed-legacy-field-after-semantic-drift)An Elastic SIEM rule goes quiet (siem-rule-followed-legacy-field-after... focuses on schema-migration and asks the reader to isolate the key signal in elastic. Field presence after a schema migration does not guarantee the field still mean...SecurityAdvanced13 minProSECURITY-1369An Ubuntu bastion patch run completes and SSH trust breaksRoutine patching succeeds and later automated SSH clients start rejecting the bastion even though no access policy was intentionally changed.SecurityAdvanced13 minProSECURITY-1381A Cloudflare mTLS policy protects the main API and one versioned path stays...A Cloudflare mTLS policy protects the main API and one versioned path stays... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Edge auth failures often come from precedence between broad exceptions a...SecurityAdvanced14 minProSECURITY-1376A fail2ban-style parser sees every request as the CDN edgeA proxy trust configuration is updated and later automated bans begin hitting CDN edges or harmless intermediaries instead of abusive clients.SecurityAdvanced14 minProSECURITY-1411An access proxy protects `/api/users` and one service endpoint still bypasses...An access proxy protects `/api/users` and one service endpoint still... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Access regressions often come from route precedence and norm...SecurityAdvanced14 minProSECURITY-1421An access proxy protects the user API and one service endpoint still bypasses...An access proxy protects the user API and one service endpoint still... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Access regressions often come from route precedence and no...SecurityAdvanced14 minProSECURITY-1431An access proxy protects the user API and one service path still bypasses MFAAn access proxy protects the user API and one service path still bypasses MFA focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Access regressions often come from route pr...SecurityAdvanced14 minProSECURITY-1441An access proxy protects the user API and one service path still bypasses...An access proxy protects the user API and one service path still bypasses... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Access regressions often come from route pre...SecurityAdvanced14 minProSECURITY-1363An Elastic API key rotation is successful and one Beats sidecar still failsCredential rotation finishes and later one ingestion path continues to return 401 despite the new secret being present in the cluster.SecurityAdvanced14 minProSECURITY-1393An OpenSearch admin SSO flow returns successfully and session validation failsAn OpenSearch admin SSO flow returns successfully and session validation fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. JWT validation issues after key rotation often live in intermediate JWKS cache...SecurityAdvanced14 minProSECURITY-1383An OpenSearch snapshot repository remains registered and backups failAn OpenSearch snapshot repository remains registered and backups fail focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Repository auth failures can persist after IAM fixes when the node keeps pre...SecurityAdvanced14 minProSECURITY-1359An Ubuntu bastion patch window completes and SSH trust breaksAn Ubuntu bastion patch window completes and SSH trust breaks focuses on Identity And Access and asks the reader to isolate the key signal in Linux. Patch windows can rotate machine identity, not just patch packages.SecurityAdvanced14 minPro