Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1349An Ubuntu bastion patch window succeeds and SSH trust breaksRoutine patching is completed and later automated SSH clients reject the bastion despite no intended access control changes.SecurityAdvanced14 minProSECURITY-1386A Cilium deny policy looks correct and one egress path remains openA Cilium deny policy looks correct and one egress path remains open focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Policy surprises often come from broader selectors attached through helper layers lik...SecurityAdvanced15 minProSECURITY-1357A Cilium FQDN policy allows a hostname and still blocks trafficA Cilium FQDN policy allows a hostname and still blocks traffic focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Name-based policy is only as correct as the DNS query that actually leaves the worklo...SecurityAdvanced15 minProSECURITY-1377A Cilium FQDN policy allows the expected hostname and traffic still failsA Cilium FQDN policy allows the expected hostname and traffic still fails focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. FQDN policies operate on real DNS observations, not on the hostname stri...SecurityAdvanced15 minProSECURITY-1336A Cilium network policy blocks unexpected egress only in one security...A Cilium network policy blocks unexpected egress only in one security... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Name-based policy decisions can stale independently from pod label...SecurityAdvanced15 minProSECURITY-1347A Cilium policy allows one FQDN and still breaks egressA secure namespace uses a service mesh sidecar and later one external dependency fails only under FQDN-based egress controls.SecurityAdvanced15 minProSECURITY-1345A Cloudflare Access protected app still exposes a management portA Cloudflare Access protected app still exposes a management port focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cloudflare. Zero Trust at the front door does not automatically secure alternate p...SecurityAdvanced15 minProSECURITY-1334A CrowdSec or Fail2ban style ban pipeline blocks the wrong sourceA CrowdSec or Fail2ban style ban pipeline blocks the wrong source focuses on incident-response and asks the reader to isolate the key signal in NGINX. Security controls that depend on source IP must be reviewed whenever the trust bo...SecurityAdvanced15 minProSECURITY-1308A CSP nonce implementation is correct at origin and still unsafeA team adds CSP nonces and later a cached HTML shell makes the same nonce appear repeatedly in production.SecurityAdvanced15 minProSECURITY-1317A GitHub Actions secret scan starts failing only forked pull requestsA GitHub Actions secret scan starts failing only forked pull requests focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Workflow security failures are often ordering bugs, not missing secret definitions.SecurityAdvanced15 minProSECURITY-1312A Grafana datasource secret rotates successfully and alert rules still failA team rotates monitoring credentials and later finds dashboards healthy while rule evaluations continue to fail with auth errors.SecurityAdvanced15 minProSECURITY-1341A Grafana SSO login succeeds and folder permissions look emptyA company refreshes its IdP schema and later Grafana users log in successfully but lose access to folders they previously owned.SecurityAdvanced15 minProSECURITY-1371A Grafana SSO login succeeds and users land as ViewersAn IdP claim cleanup lands and later every Grafana login works but the expected team roles stop being assigned.SecurityAdvanced15 minProSECURITY-1305A Palo Alto URL allow rule exists and users still see a block pageA URL is explicitly allowed and users still cannot reach it through one firewall path after a decryption policy change.SecurityAdvanced15 minProSECURITY-1380A Terraform-managed OIDC trust update is applied and one workspace still...A Terraform-managed OIDC trust update is applied and one workspace still... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. Remote runners can retain assumptions about trust material even...SecurityAdvanced15 minProSECURITY-1320A WAF blocks only one JSON API (waf-header-normalization-breaks-one-api-client)A WAF blocks only one JSON API (waf-header-normalization-breaks-one-api... focuses on protocol-interoperability and asks the reader to isolate the key signal in Cloudflare. Parser changes can surface client quirks that were always present but pr...SecurityAdvanced15 minProSECURITY-1339A WAF challenge policy protects the main app and still exposes one admin routeA WAF challenge policy protects the main app and still exposes one admin route focuses on Deployment Governance and asks the reader to isolate the key signal in NGINX. Security includes can look global while still missing routes defined in separate...SecurityAdvanced15 minProSECURITY-1330A zero trust policy allows the service token and the backend still returns 403A zero trust policy allows the service token and the backend still returns 403 focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Zero Trust success at the edge does not guarantee the origin app...SecurityAdvanced15 minProSECURITY-1327An admission policy rollout breaks only one namespaceAn admission policy rollout breaks only one namespace focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Distributed trust injection systems rarely converge everywhere at the same instant.SecurityAdvanced15 minProSECURITY-1350An AWS OIDC trust policy matches the cluster issuer and one controller still...An AWS OIDC trust policy matches the cluster issuer and one controller... focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared IaC can still emit stale identity data if one workspace cached old metadata.SecurityAdvanced15 minPro