Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1360An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity maintenance task succeeds broadly and later one controller in one environment alone continues failing IRSA or web-identity auth.SecurityAdvanced15 minProSECURITY-1370An AWS OIDC trust refresh fixes most clusters and one controller still failsA cluster identity refresh completes and later only one environment continues to fail IRSA or web-identity auth for a controller.SecurityAdvanced15 minProSECURITY-1315An AWS STS AssumeRoleWithWebIdentity call works from one workload and fails...An AWS STS AssumeRoleWithWebIdentity call works from one workload and fails... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. STS web identity failures often come from audience mismatch even when issuer and subje...SecurityAdvanced15 minProSECURITY-1340An AWSKRUG-style EKS access pattern uses OIDC and still breaks one controllerAn AWSKRUG-style EKS access pattern uses OIDC and still breaks one controller focuses on Deployment Governance and asks the reader to isolate the key signal in AWS. Shared Terraform code can still render different identity assumptions if...SecurityAdvanced15 minProSECURITY-1353An Elastic API key rotates successfully and one Beats sidecar keeps 401ingA credential rotation is completed and later one logging path continues to fail even though the secret update is visible in the cluster.SecurityAdvanced15 minProSECURITY-1331An Elastic API key rotation succeeds and one Beats pipeline still gets 401An Elastic API key rotation succeeds and one Beats pipeline still gets 401 focuses on Identity And Access and asks the reader to isolate the key signal in Linux. Key rotation success in storage does not prove the runtime consumer has...SecurityAdvanced15 minProSECURITY-1343An Elastic ingest pipeline keeps 401ing (elastic-sidecar-kept-using-projected-old-api-key-volume)An Elastic ingest pipeline keeps 401ing (elastic-sidecar-kept-using-projected... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Cluster secret updates do not automatically mean every pod reop...SecurityAdvanced15 minProSECURITY-1329An IdP secret rotation succeeds and one workload still failsAn OIDC signing key is rotated and only one service path keeps rejecting freshly minted tokens for a while afterward.SecurityAdvanced15 minProSECURITY-1372An OpenSearch dashboard SSO flow works on GET and failsAn OpenSearch dashboard SSO flow works on GET and fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Cross-site POST returns are especially sensitive to SameSite policy changes around proxy and...SecurityAdvanced15 minProSECURITY-1332An OpenSearch role mapping looks correct and SSO users still lose accessAn OpenSearch role mapping looks correct and SSO users still lose access focuses on Deployment Governance and asks the reader to isolate the key signal in Linux. An auth token can contain the right roles under the wrong shape for a plugin th...SecurityAdvanced15 minProSECURITY-1324An SSH certificate rollout is correct and clients still choose the wrong identityA certificate-based SSH migration is rolled out and some users still fail even though the correct certificate is present in their environment.SecurityAdvanced15 minProSECURITY-1277A CDN or reverse proxy rate limit looks strict but password spray still landsAn authentication surface keeps seeing spray attempts after per-IP limits are lowered aggressively.SecurityAdvanced16 minProSECURITY-1311A Cloudflare Access policy looks correct and one API still returns 403An internal API is moved behind a new Access application and only some users keep seeing 403 responses from a browser session that otherwise looks authenticated.SecurityAdvanced16 minProSECURITY-1318A Kubernetes admission webhook serves valid TLS and requests still failA cluster rotates webhook serving certs in place and later admission failures appear even though the pod and service remain healthy.SecurityAdvanced16 minProSECURITY-1297A rate limiter on login works against direct traffic but notA rate limiter on login works against direct traffic but not focuses on incident-response and asks the reader to isolate the key signal. A rate limiter is only as strong as the identity header or source it trusts.SecurityAdvanced16 minProSECURITY-1262A SameSite cookie setting breaks SSO only on one browser pathSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced16 minProSECURITY-1264A secret leak alert keeps returningSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced16 minProSECURITY-156A SIEM dashboard shows the new field names, but the scheduled incident export still queries the old schema and sends empty nightly reportsInteractive analysis is fine, yet one automated reporting path still depends on the legacy field map.SecurityAdvanced16 minProSECURITY-1295A signed cookie works on one subdomain and fails on anotherA cross-subdomain auth feature works on one hostname and fails only when routed through a CDN alias or alternate domain.SecurityAdvanced16 minProSECURITY-1301A Vault AppRole login succeeds and database credentials still expire earlyAn app authenticates with AppRole and later loses its dynamic credentials long before the advertised secret lifetime should end.SecurityAdvanced16 minPro