CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-216Runtime credential caches keep serving access long after central revocation completed during a failover rehearsalThe security team acts quickly and the runtime still lives in the past. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-079Secrets Manager rotation succeeds but the application keeps reading the old current version stageThe rotation Lambda finishes, yet the service still fails login because the stage labels and the consumer refresh path are out of sync.SecurityAdvanced18 minProSECURITY-099Security group egress hardening blocks the OCSP responder and only strict TLS clients fail validationCertificates are current, yet a subset of clients fail because the server-side environment can no longer complete revocation checks through the hardened egress policy.SecurityAdvanced18 minProSECURITY-085Session revocation works centrally but one edge node continues accepting the old JWT until its cache expiresThe revoke event is recorded correctly, yet some requests still succeed because one verifier node has not refreshed its token or key cache.SecurityAdvanced18 minProCICD-113Signing verifies the tarball provenance but deployment consumes an OCI reference that was never attestedThe release report shows a verified artifact, but the runtime image came from a different reference path than the object the signing step covered.CI/CDAdvanced18 minProSECURITY-091SSO works but step-up MFA never triggersPrimary authentication succeeds, yet privileged actions remain exposed because the application is still reading an outdated assurance claim.SecurityAdvanced18 minProSECURITY-1215Temporary WAF bypass is removed centrally but one edge path still behaves as if the exception remainsThe source of truth is clean, yet traffic still flows through an old exception because rollout state diverged across edge nodes or configs.SecurityIntermediate18 minProSECURITY-139The reverse proxy and WAF normalize duplicate headers differently, creating a request-smuggling edge case on one legacy routeMost paths are safe, but one parsing mismatch keeps a classic multi-hop ambiguity alive.SecurityAdvanced18 minProSECURITY-174Two request-processing layers normalize the same input differently and one legacy route stays bypassable during a failover rehearsalMultiple security layers inspect the request and disagree on what the request really is. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-1224WAF rollback looks complete but one hostname still enforces the old ruleA temporary block is reverted and most traffic returns to normal, but one API hostname still rejects the old pattern.SecurityAdvanced18 minProSECURITY-1219WAF rule rollback looks complete but one API hostname still enforces the old behaviorA temporary block is reverted and most traffic returns to normal, but one API hostname still rejects the old pattern.SecurityAdvanced18 minProSECURITY-1263A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers-different-waf-signals)A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Azure. A WAF rule tuned for one header and proxy shape can still fail on alternate h...SecurityAdvanced19 minProSECURITY-1268A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers-different-waf-signals)A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Azure. A WAF rule tuned for one header and proxy shape can still fail on alternate h...SecurityAdvanced19 minProSECURITY-1259An allowlist protects the main admin hostname but a second hostname still reaches the same backend through another proxy chainThe edge policy works on the documented URL, yet another hostname bypasses it because the backend is still exposed through a different path.SecurityAdvanced19 minProSECURITY-081Conditional Access excludes the break-glass user but not the device-registration prerequisiteThe emergency account is excluded from the main policy, yet login still fails because an upstream prerequisite step is governed by a different device rule set.SecurityAdvanced19 minProSECURITY-1214CSP looks right but federated login popup still failsA CSP hardening change seems safe until popup or embedded identity flows start failing for some users.SecurityAdvanced19 minProSECURITY-1243mTLS appears correct but one client still failsOne runtime image connects successfully while another fails mTLS against the same upstream even though both trust the same root.SecurityAdvanced19 minProSECURITY-1233mTLS looks configured correctly but one client still failsOne client image connects successfully while another fails to complete the mutual TLS handshake against the same service.SecurityAdvanced19 minProSECURITY-1253mTLS looks correct but one client still failsOne runtime image connects successfully while another fails against the same upstream despite sharing the same root trust.SecurityAdvanced19 minProSECURITY-1248mTLS looks correct on paper but one client still failsOne client runtime connects successfully while another fails against the same upstream despite using the same trusted root set.SecurityAdvanced19 minPro