CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-080Endpoint isolation policy blocks the EDR cloud callback and the host never recovers from containmentContainment starts correctly, but the host stays permanently isolated because the policy also cut off the control channel required to release it safely.SecurityAdvanced21 minProSECURITY-1211Federated login breaks only on callbackAn OIDC flow still reaches the provider successfully, but the callback handler rejects the return due to missing browser state.SecurityAdvanced21 minProSECURITY-1189IAM role rotation looks complete but long-lived pods keep using stale credentialsA cloud role was rotated and policy updated, yet running workloads continue to fail or over-permit because old credentials remain cached in process state.SecurityAdvanced21 minProCICD-099Image signing succeeds in CI but the admission policy rejects the signature issuer after root rotationThe build publishes a signed image, yet cluster admission fails because the verifier still trusts the old signing root only.CI/CDAdvanced21 minProK8S-066Projected service account token audience mismatch breaks external Vault authThe pod has a valid token, but external auth still fails because the verifier expects a different audience than the projected token request generated.KubernetesAdvanced21 minProK8S-081Readiness passes but Envoy sidecar cannot reach the control plane after a trust bundle splitThe app container is healthy, yet traffic still fails because the sidecar lost trust in the mesh control plane after the certificate bundle changed unevenly.KubernetesAdvanced21 minProSECURITY-062SIEM correlation deduplicates brute-force alerts and hides the real spray scopeAnalysts see only a few incidents, but the attack is much wider because the correlation rule collapses repeated signals into one coarse event group.SecurityAdvanced21 minProSECURITY-084WAF JSON parser normalizes the body differently from the application and bypasses the intended block ruleSecurity rules appear present, but a crafted request still reaches the app because the protection layer interprets the JSON structure differently from the backend.SecurityAdvanced21 minProSECURITY-075An SCP allows the recovery service but blocks the dependent KMS decrypt call during restoreThe incident playbook launches correctly, but restore still fails because the organization policy forgot the downstream KMS permission the service actually needs.SecurityAdvanced22 minProSECURITY-057Certificate pinning fails only on the guest network after SSL inspection is enabledThe app works on trusted networks, but mobile users on the guest path fail because the intercepted certificate no longer matches the pinned expectation.SecurityAdvanced22 minProSECURITY-087CloudTrail organization trail exists but one delegated admin account writes to an unmonitored bucket in another regionAudit coverage seems complete, yet one privileged path is effectively invisible because the delegated admin is using a destination outside the monitored collection pattern.SecurityAdvanced22 minProSECURITY-070EDR quarantine removes the log shipper binary and host visibility disappears without an alertThe endpoint agent did its job from one perspective, but security operations lose telemetry because the quarantined component was also the only path to central visibility.SecurityAdvanced22 minProK8S-068FailurePolicy Ignore lets pods start without the required security sidecarThe cluster stays available during webhook trouble, but production traffic later fails because workloads launched without the sidecar contract the platform assumes.KubernetesAdvanced22 minProSECURITY-031IAM role trust policy rejects GitHub OIDC tokenThe workflow reaches the cloud provider, but the trust policy denies the token because the expected audience or subject does not match the actual issuer claims.SecurityIntermediate22 minProSECURITY-1210mTLS rotation looks complete but one gateway still failsAn mTLS rotation completes and most gateways recover, but one still rejects peers because its chain trust is incomplete.SecurityAdvanced22 minProSECURITY-1201OIDC issuer update looks complete but one validator still pins the old issuer URLMost auth flows recover after an issuer migration, yet one proxy or sidecar still rejects tokens because it continues to trust the previous issuer location.SecurityAdvanced22 minProSECURITY-1184OIDC login callback breaks behind proxyCommunity fixes focus on the identity provider, but the real break is that the edge proxy is building the wrong callback URL.SecurityAdvanced22 minProK8S-087OIDC provider issuer URL rotates and every projected token verifier in the cluster rejects new tokensToken projection still works, but consumers fail because the issuer trust path and JWKS discovery URL changed underneath long-lived verifiers.KubernetesAdvanced22 minProSECURITY-065Vault periodic token stops renewingThe workload starts normally, but long-lived sessions fail hours later because the renewal path assumed a parent-child token chain that no longer exists.SecurityAdvanced22 minProSECURITY-1191WAF allows the obvious route but still misses the attackA WAF rollout follows public guidance and appears healthy. Later, testing shows the same app is still reachable through an alternate hostname that bypasses the protected edge path.SecurityAdvanced22 minPro