Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1228mTLS trust looks correct but one client still failsA service-to-service connection works from one client image and fails from another despite apparently identical certificates.SecurityAdvanced19 minProSECURITY-088Mutual TLS is enabled but the CRL endpoint is unreachable and only strict clients reject the serverCertificates are otherwise valid, but some clients fail because they require revocation checking and the CRL distribution path is no longer reachable.SecurityAdvanced19 minProSECURITY-093Secrets rotation updates the database user but leaves a cached connection pool authenticating with the old passwordThe new credential is valid, yet outages continue because the application pool never discarded existing sessions that still reuse the previous password flow.SecurityAdvanced19 minProSECURITY-1216Secure cookie and redirect settings look correct but one browser still loopsFederated login works in one hostname path but another branded hostname falls into a redirect loop after successful auth.SecurityAdvanced19 minProSECURITY-074Secure proxy strips WebSocket auth headers and the browser terminal stops connectingRegular HTTP browsing still works, but the interactive terminal path fails because the proxy policy handles upgraded connections differently from standard requests.SecurityAdvanced19 minProSECURITY-1218Abuse detection misses distributed attacksAn application sometimes receives traffic through the CDN and sometimes directly, but logging logic always trusts the forwarded IP header.SecurityAdvanced20 minProSECURITY-1223Abuse detection misses distributed attacksAn application sometimes receives traffic via CDN and sometimes directly, but the detector always trusts the same forwarded header.SecurityAdvanced20 minProSECURITY-1249An admin surface seems protected by an edge allowlist but an alternate hostname still bypasses it through another proxy chainThe main route is locked down, yet the same backend remains reachable through a secondary hostname that never traverses the allowlisted edge path.SecurityAdvanced20 minProSECURITY-1244An edge allowlist looks correct but an alternate hostname still exposes the admin surfaceA team secures the public admin entry and later finds an internal or legacy hostname still exposes it without the same edge restrictions.SecurityAdvanced20 minProSECURITY-1254An edge allowlist seems correct but an alternate hostname still bypasses it through another proxy chainThe main route is protected, yet the same backend remains reachable through a secondary hostname that never traverses the allowlisted edge path.SecurityAdvanced20 minProSECURITY-1234An edge allowlist seems correct but one alternate hostname still exposes the admin surfaceA team locks down an admin interface and later discovers an internal or legacy hostname still reaches the same endpoint without the edge policy.SecurityAdvanced20 minProSECURITY-1229An IP allowlist is present at the edge but admin traffic still leaks throughThe team secures the public hostname and later discovers an alternate internal or legacy hostname still exposes the same admin interface.SecurityAdvanced20 minProSECURITY-1185AWS security group looks correct but EKS API access still failsA team follows networking advice from public threads and proves the API endpoint is reachable. Access still fails because the cluster does not trust the caller identity.SecurityAdvanced20 minProSECURITY-1213Brute-force detection looks quietA login surface sits behind multiple proxies and the detection pipeline treats one forwarded header as authoritative.SecurityAdvanced20 minProSECURITY-072IAM permission boundary blocks emergency admin role assumption despite the attached allow policyThe incident role seems fully privileged, but assumption still fails because the boundary silently caps effective access below the attached policy intent.SecurityAdvanced20 minProSECURITY-066JWKS cache on the API gateway stays stale after OIDC signing key rotationThe identity provider is healthy and publishes the new key, but valid tokens still fail because the gateway never refreshed its cached trust material in time.SecurityAdvanced20 minProSECURITY-083KMS grant allows encrypt but one rotated alias points the application to a key without decrypt permissionThe secret path still looks valid, yet runtime failures begin because the alias now resolves to a different key than the policy and grants were built for.SecurityAdvanced20 minProSECURITY-089SIEM suppression rule hides the second stage of an attackThe first alerts are known noise, but the actual compromise gets hidden because the suppression logic keys on a reused naming pattern across rebuilt hosts.SecurityAdvanced20 minProSECURITY-100Vault seal migration completes on the leader but one standby still advertises stale recovery key requirementsThe cluster seems healthy, yet operational confusion persists because one standby node still reflects the previous seal-state assumptions after migration.SecurityAdvanced20 minProSECURITY-1193Cloud audit agent looks healthy but stopped shipping logs after a service-account rotationThe agent process runs, yet the audit pipeline is effectively dark because the credential or permission path it uses no longer matches the rotated identity.SecurityAdvanced21 minPro