CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-125A SIEM suppression for the vulnerability scanner hides real lateral movementNoise reduction worked for one source, but the coarse suppression pattern now covers genuine malicious activity.SecurityAdvanced17 minProSECURITY-381A snapshot policy copies encrypted data correctlyA snapshot policy copies encrypted data correctly focuses on cloud-security-and-governance and asks the reader to isolate Permission Denied in AWS. 실무에서는 permission-denied 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다.SecurityAdvanced17 minProSECURITY-105A WAF bypass exception for health checks accidentally matches the admin route prefix after a path refactorMonitoring stays green, but a protection hole opens because the relaxed path rule now overlaps with privileged endpoints.SecurityAdvanced17 minProSECURITY-143A WAF custom rule matches on decoded path segments, but the reverse proxy evaluates the raw form and one legacy route stays bypassableBoth layers inspect the request, yet they do not interpret the path in the same representation.SecurityAdvanced17 minProSECURITY-1293A WAF rule tuned for the main hostname still blocks the canary pathA canary environment behind the same WAF behaves differently even after the rule was tuned against production traffic.SecurityAdvanced17 minProSECURITY-135An AWS IAM permissions boundary copied from a template blocks kms:Decrypt in the break-glass role and recovery automation fails during an incidentThe emergency role exists, yet one inherited boundary quietly removes the exact permission the runbook requires.SecurityAdvanced17 minProSECURITY-154An IAM role trust policy is updated for the new OIDC issuer, but the condition key still references the old provider path and federated deploys failThe identity provider appears swapped successfully, yet the claim-matching logic is still anchored to the previous issuer structure.SecurityAdvanced17 minProSECURITY-150An incident containment playbook revokes the VM role, but the host's metadata proxy cache keeps serving old credentials for several minutesThe control plane moved fast, yet runtime revocation lag created a dangerous grace period.SecurityAdvanced17 minProSECURITY-1279An intermediate certificate is installed on the server, but older clients still failA certificate incident appears fixed by file inspection and only certain client families continue to fail.SecurityAdvanced17 minProSECURITY-096AWS IAM role session policy shrinks access below the base role and only one Lambda path fails decryptThe role seems correct, yet decryption still fails because the assumed session adds a restrictive inline policy at invocation time.SecurityAdvanced17 minProSECURITY-092Cloud WAF blocks the admin API path only after a new JSON field increases rule score above thresholdThe endpoint worked before, but the updated payload shape now trips a scoring-based rule model that was previously below the block threshold.SecurityAdvanced17 minProSECURITY-102Just-in-time admin approval succeeds, but the bastion PAM cache still enforces the previous group membershipOperators receive the right entitlement in the identity plane, yet the bastion keeps denying access until its local authorization cache expires.SecurityAdvanced17 minProSECURITY-109SCIM deprovision disables the SaaS account, but a long-lived personal token still lets the former admin call the APIIdentity offboarding appears complete in the UI, yet API access remains because one token type was never linked to account lifecycle enforcement.SecurityAdvanced17 minProSECURITY-159The mTLS certificate chain validates externally, but the internal proxy strips the client certificate header on HTTP/2 upgrade and backend auth fails only thereTransport security is intact, yet identity propagation across layers is not.SecurityAdvanced17 minProSECURITY-318A backup or snapshot path is readable while cross-account or cross-region recovery still lacks the exact decrypt or restore permission it needs during a failover rehearsalThe artifact exists and the recovery scope where it matters is still unauthorized. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-234A backup snapshot restores while the copy role still lacks the right to re-encrypt in the target account during a failover rehearsalDisaster recovery looks viable until the protected copy has to become live elsewhere. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-330A break-glass or emergency path bypasses one identity control while another session or device rule still revokes it before the task finishes during a failover rehearsalThe emergency door opens and another control closes it before recovery is done. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-1231A browser login loop persists after successful OIDC callbackOne hostname or browser completes the login flow and another loops forever even though the provider logs show success.SecurityAdvanced18 minProSECURITY-1283A certificate bundle looks current on disk but one Java client still failsA certificate bundle looks current on disk but one Java client still fails focuses on protocol-interoperability and asks the reader to isolate the key signal. Trust material correctness depends on the verifier's path-building behavior,...SecurityAdvanced18 minProSECURITY-180A cloud permission exists in one region while the recovery workflow executes in another scope during a failover rehearsalThe right grant is present and absent at the same time depending on where the workflow actually runs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minPro