CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-228A custom WAF response hides the real block reason while upstream retries amplify the same exploit attempt internally during a failover rehearsalThe control works and one observability decision turns it into operational noise. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-324A mutual TLS path validates at the edge while revocation checks or identity forwarding fail later in the request chain during a failover rehearsalTransport setup succeeds and the secure identity contract breaks farther downstream. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-124A presigned URL is valid, but the CDN cache key ignores one scoping parameter and content becomes reusable outside the intended request contextObject access control is strong at origin, yet the edge cache weakens it by collapsing distinct authorization contexts.SecurityAdvanced18 minProSECURITY-160A ransomware isolation workflow snapshots the volumes correctly, but the snapshot retention tag is missing and cleanup automation deletes the evidence before triage startsContainment worked, yet incident preservation failed because the evidence path lacked lifecycle protection.SecurityAdvanced18 minProSECURITY-104A rotated KMS key policy omits the legacy alias and historical backup decrypt operations fail during recoveryNew encrypt operations work, but restore testing fails because the recovery path still references an alias that the new policy no longer permits.SecurityAdvanced18 minProSECURITY-282A trust policy validates the new OIDC issuer while one condition key still matches the old claim path during a failover rehearsalThe provider migration is half-complete and federated access still fails on the detail that matters. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-1275A WAF tune fixes the primary hostname but the same application still fails on a second hostnameA false positive fix is validated on the main public route and users still break through a legacy or alternate hostname.SecurityAdvanced18 minProSECURITY-210An authorization token is valid for one delivery host while the content path crosses into another during a failover rehearsalAuthorization is scoped correctly and the asset path does not stay where the token applies. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-168An emergency account bypasses the first control while a downstream session rule still revokes it too early during a failover rehearsalThe break-glass path escapes one identity gate and remains constrained by another. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-111CloudTrail shows the access denies, but the missing service-linked role auto-creation was never logged in the regional trail you checkedThe permissions symptom is real, yet the causal event lives in a different audit scope than the one the team has been searching.SecurityAdvanced18 minProSECURITY-399Containment isolates egress from compromised hosts while the forensic image or memory capture workflow still depends on an outbound escrow service during a staged decommissionThe incident is contained and the evidence pipeline quietly breaks. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced18 minProSECURITY-078JIT provisioning creates duplicate accounts after the immutable identity key changesFederation remains healthy, but every login now spawns another local account because the stable identity key changed from email to a new immutable identifier.SecurityAdvanced18 minProSECURITY-1261JWT verification breaks after key rotationSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced18 minProSECURITY-1266JWT verification breaks after key rotationA planned key rotation is executed cleanly and one application still begins rejecting newly signed tokens.SecurityAdvanced18 minProSECURITY-1258mTLS appears configured correctly but some clients still failOne client library connects to a service successfully while another fails with trust errors against the same endpoint.SecurityAdvanced18 minProSECURITY-107mTLS client identity maps to the wrong tenantCertificates are valid, yet authorization fails because the parser extracts a different identity field than the policy engine expects.SecurityAdvanced18 minProSECURITY-094mTLS handshake succeeds to the proxy but upstream certificate pinning breaks only on one pathThe edge trust path looks correct, yet the service still fails because an internal hop enforces a different certificate identity contract.SecurityAdvanced18 minProSECURITY-1265mTLS succeeds for one hostname but fails for another on the same serviceSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced18 minProSECURITY-1270mTLS succeeds for one hostname but fails for another on the same serviceA service behind one proxy works for its main hostname and starts failing trust or hostname checks on another alias.SecurityAdvanced18 minProSECURITY-1273One hostname behind the same proxy passes mTLS while another failsA service behind one proxy works on its primary hostname and fails on an alternate alias that was assumed to be equivalent.SecurityAdvanced18 minPro