CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
Let's Encrypt auto-renewal kept failing until the certificate expiredLet's Encrypt auto-renewal kept failing until the certificate expired is a hands-on troubleshooting drill. Find why ACME HTTP-01 renewals failed silently and fix the challenge path and monitoring. TLS and Certificate Chain needs to be checked by narrowing scope, recent change,...ReviewedSecurityIntermediate16 minFreeS3 AccessDenied: the IAM policy allows it but the bucket policy denies itS3 AccessDenied: the IAM policy allows it but the bucket policy denies it is a hands-on troubleshooting drill. Read the explicit-deny wording in AccessDenied and fix access through the approved path. AWS cloud-security-and-governance needs to be checked by narrowing scope, rec...ReviewedSecurityIntermediate17 minFreeCORS blocks the new admin frontend's API calls with credentialsCORS blocks the new admin frontend's API calls with credentials is a hands-on troubleshooting drill. Read the browser's CORS error precisely and return the right headers for credentialed requests. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, a...ReviewedSecurityBeginner14 minFreeSECURITY-039S3 server access log archive fails after object ownership policy changedCentral logging was working until bucket ownership controls changed, and now write attempts fail even though the destination bucket still exists and the prefix is correct.SecurityIntermediate19 minFreeSECURITY-052ACME HTTP-01 renewal failsTLS worked yesterday, but automated renewal now fails because the well-known challenge route is treated like an untrusted request pattern by the current edge policy.SecurityIntermediate20 minFreeSECURITY-097Conditional access trusts the compliant device claim but the token was minted before the device fell out of complianceThe policy is sound, yet a risky session survives because token lifetime outlasts the compliance state transition the team expected to revoke it instantly.SecurityIntermediate15 minFreeSECURITY-152A browser isolation policy renders the admin portal remotely, but a direct-download allowlist still lets CSV exports bypass the isolated sessionThe riskiest interaction is protected, yet a side path still leaks the sensitive payload.SecurityIntermediate16 minFreeSECURITY-146A SIEM parser now splits IPv6 addresses and ports correctly, but one detection rule still assumes IPv4 colon counts and silently stops matchingThe data quality improved, yet one analytic depended on the previous broken representation.SecurityIntermediate16 minFreeSECURITY-077Custom WAF allow rule matches but a later managed rule still blocks the requestThe operator sees the expected custom rule fire, yet traffic remains blocked because the final decision is made by a later managed rule with stronger action priority.SecurityIntermediate16 minFreeSECURITY-086Federated logout succeeds in the IdP but leaves the local admin session alive on the legacy appThe user appears signed out globally, but the legacy admin panel still accepts requests because its local session invalidation is not coupled to federation logout.SecurityIntermediate16 minFreeSECURITY-068MFA-enforced sudo flow breaks non-interactive automation on one hostThe stronger policy is correct for humans, but the service account path now fails because the exempt automation group was never applied consistently.SecurityIntermediate16 minFreeSECURITY-071OAuth login fails after a vanity-domain cutoverThe app and IdP are healthy, but authentication loops because the new branded callback path does not exactly match the registered redirect URI set.SecurityIntermediate16 minFreeLINUX-075pam_faillock keeps accounts blocked after LDAP recoveryDirectory authentication is healthy again, but users still cannot log in because the host-local lock records survived the upstream outage.LinuxIntermediate16 minFreeLINUX-089rsync backup over SSH stallsNetwork reachability is fine, but the batch backup never starts because the negotiated SSH crypto overlap disappeared during a hardening change.LinuxIntermediate16 minFreeSECURITY-192A parser becomes more correct while one detection silently depends on the old broken field shape during a failover rehearsalData quality improves and a rule built on yesterday's bug stops matching. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-288A parser normalization fix improves usernames while scheduled SIEM exports still query the old field shapes and emit empty reports during a failover rehearsalDashboards look healthy and nightly reporting continues living in the previous schema. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-240A telemetry parser lowercases usernames while one detection still depends on the old mixed-case service account form during a failover rehearsalThe data is normalized and one analytic still expects the previous representation. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-076EKS IRSA token file becomes unreadable after a sidecar changes the shared volume ownershipThe role mapping is correct, but the application cannot assume it because the projected token path no longer matches the runtime user permissions after a sidecar update.SecurityIntermediate17 minFreeSECURITY-082TLS offload proxy re-encrypts with a deprecated cipher set and only one partner API rejects itClient-facing certificates look modern, but one partner integration breaks because the upstream re-encryption profile still uses a weaker legacy policy.SecurityIntermediate17 minFreeSECURITY-064WAF bot challenge protects the browser path but blocks webhook callbacks from non-browser clientsThe site is safer for humans, but an integration silently breaks because the challenged path now assumes browser behavior that the webhook sender never provides.SecurityIntermediate17 minFree