Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1313A Vault AppRole rollout works in staging and fails in productionA Vault AppRole rollout works in staging and fails in production focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. CIDR-bound auth often fails on hidden NAT differences rather than on Vault role misconfigu...SecurityAdvanced16 minProSECURITY-1304A WAF custom rule blocks only the canary URLA security team tunes a WAF rule for production traffic and only the canary path keeps failing with the same signature.SecurityAdvanced16 minProSECURITY-1321An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy-change)An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. OIDC loops often come from callback identity drift rather than from bad user cr...SecurityAdvanced16 minProSECURITY-121An OAuth token exchange succeeds, but the resource server clock skew rejects the just-issued JWT as not yet validIdentity is correct, yet token freshness assumptions differ across the two systems.SecurityAdvanced16 minProSECURITY-1303Cloudflare Access protects the app generally and one cached path reaches the origin without identity headersAn origin trusts CF Access headers and later one static-like route starts reaching it without the expected identity context.SecurityAdvanced16 minProSECURITY-098CloudFront signed cookie scope excludes the websocket upgrade host and only the browser terminal loses authStatic pages load normally, but the interactive browser tool fails because the signed cookie domain or path does not cover the upgraded endpoint host.SecurityAdvanced16 minProSECURITY-1309mTLS resumes fine after certificate rotation on one service and fails on anotherA rotation campaign updates bundles cluster-wide and only one workload or sidecar continues failing mutual TLS handshakes.SecurityAdvanced16 minProSECURITY-1310Secret scanning alerts keep firing after rotationA team rewrites history and rotates secrets successfully, but alerts keep reappearing from what looks like a clean repository.SecurityAdvanced16 minProSECURITY-095SIEM parser update collapses two source IP fields and the threat hunt queries miss half the trafficLogs are arriving, but hunting results look incomplete because the updated parser rewrote field names that saved searches still depend on.SecurityAdvanced16 minProSECURITY-393A break-glass access role bypasses MFA (Auth and Session Failure)A break-glass access role bypasses MFA (Auth and Session Failure) focuses on Identity and Access Management and asks the reader to isolate Auth and Session Failure in Azure. 실무에서는 auth-and-session-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로...SecurityAdvanced17 minProSECURITY-357A certificate replacement installs the right chainA certificate replacement installs the right chain focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 certificate-trust-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점...SecurityAdvanced17 minProSECURITY-149A CloudFront signed URL policy covers the main asset host, but a redirect to the image host drops the signature scope and private media leaks a 403 loopThe control is present, yet the delivery path crosses hostnames that do not share the same authorization contract.SecurityAdvanced17 minProSECURITY-345A federated login trust points at the correct issuer while the downstream application still enforces the old audience or group claim mapping during a staged decommissionAuthentication succeeds at the identity edge and authorization fails where claims are interpreted differently. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced17 minProSECURITY-118A hardware token step-up is required on paper, but the mobile fallback policy silently downgrades privileged actions to SMSAdministrators believe strong authentication protects the action, yet one fallback rule lets the mobile app satisfy the control with a weaker factor.SecurityAdvanced17 minProLINUX-120A kernel livepatch package loads successfully but the target symbol version mismatch means the host remains vulnerableThe livepatch service reports success, yet the running kernel never actually applies the fix because the binary compatibility window was missed.LinuxAdvanced17 minProSECURITY-387A mutual TLS edge validates the client certificateA mutual TLS edge validates the client certificate focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 auth-and-session-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점의...SecurityAdvanced17 minProSECURITY-375A reverse proxy or isolation layer protects browser trafficA reverse proxy or isolation layer protects browser traffic focuses on WAF and AppSec Controls and asks the reader to isolate Permission Denied in NGINX. 실무에서는 permission-denied 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. WAF / AppSec 관점...SecurityAdvanced17 minProSECURITY-1299A service mesh identity update looks correct but one gateway rejects mTLSA workload migration between trust domains succeeds broadly and one ingress or egress gateway alone starts rejecting mTLS peers.SecurityAdvanced17 minProSECURITY-1285A service mesh mTLS policy looks identical across namespaces but one namespace still failsA mesh-wide trust update succeeds broadly and one namespace alone begins failing mTLS handshakes immediately afterward.SecurityAdvanced17 minProSECURITY-110A SIEM correlation rule misses an after-hours brute-force chainRaw events arrive, but the analytic never fires because time bucketing no longer aligns with the intended incident window.SecurityAdvanced17 minPro