CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-1183AWS WAF blocks a safe admin pathA team enabled an AWS managed rule set following public guidance. An internal admin path now breaks because its request pattern trips a generic rule.SecurityAdvanced23 minProSECURITY-1203Central log pipeline is green but one parser update silently drops a whole class of security eventsCollection is alive and dashboards look healthy, yet one format change causes a parser to reject or discard a subset of events without obvious pipeline failure.SecurityAdvanced23 minProSECURITY-1198Cloud audit trail is complete in one account but gaps appearA multi-account logging design followed public cloud guidance. A permission change in one account now creates partial visibility loss that is easy to miss from the central console.SecurityAdvanced23 minProSECURITY-1195Cloud role assumption succeeds in one region and fails in anotherA cloud auth rollout followed community guidance and worked in one region. A second region fails because the trust condition still expects the previous audience or issuer pattern.SecurityAdvanced23 minProSECURITY-053CSP nonce is generated correctly but disappears after CDN template cachingThe application renders a fresh nonce, yet the browser still blocks the script because the cached edge fragment reuses a stale header-body combination.SecurityAdvanced23 minProSECURITY-063KMS policy lets backup jobs encrypt but restore jobs cannot decrypt in the recovery accountBackups complete successfully, yet every restore attempt fails because the disaster-recovery account was never granted the full decrypt path for the same key.SecurityAdvanced23 minProSECURITY-090Vault unseal succeeds but one performance standby still serves stale auth configuration after leader failoverThe cluster looks healthy again, yet some login paths still fail because a standby node continues using old auth backend settings after control-plane leadership changed.SecurityAdvanced23 minProSECURITY-1207WAF blocks the obvious payload but a normalized path still reaches the backend through an alternate routeThe rule looks effective in one test, yet another path representation slips through because proxy and WAF normalize differently.SecurityAdvanced23 minProSECURITY-038CDN caches an authenticated error pageThe login path itself is correct, but one personalized failure response gets cached at the edge and leaks confusing content to later users.SecurityAdvanced24 minProSECURITY-1205Client certificate rotation is healthy on the app tier but one gateway still trusts the previous intermediate onlyRotated client certs work through one path and fail through another because the gateway layer did not receive the same intermediate CA update as the application tier.SecurityAdvanced24 minProSECURITY-1181Internal registry trust breaksOperators rotate certificates after reading public advice, but only one served path is broken because it omits the intermediate chain.SecurityAdvanced24 minProSECURITY-051JWKS key rotation reaches the web tier but one API pod still caches the old signerLogin works on some paths, yet token validation fails intermittently because one long-lived process never refreshed the current signing keys.SecurityAdvanced24 minProSECURITY-1200mTLS breaks only on rotated clientsA certificate rollout follows community guidance and appears fine on servers. Client auth still fails on one path because not every validator tier received the new intermediate bundle.SecurityAdvanced24 minProSECURITY-069Organization-wide CloudTrail is enabled but one region never uses the expected KMS keyAudit logging exists everywhere, yet one region violates the encryption standard because replication and key policy assumptions drifted apart over time.SecurityAdvanced24 minProNETWORK-056Site-to-site VPN comes up but traffic still needs NAT exemption for the internal subnetIKE and tunnel status look healthy, but packets still do not pass because the interesting traffic is translated before it can match the VPN policy.NetworkAdvanced24 minProNETWORK-053ECMP asymmetry breaks return traffic when one hop is statefulForward traffic succeeds across equal-cost paths, but responses vanish because a stateful device on one branch never sees the original session creation.NetworkAdvanced25 minProSECURITY-055EDR quarantine removes the log shipper binary and blinds central visibilityContainment works on the compromised host, but the action also stops telemetry collection and makes the rest of the investigation much harder.SecurityAdvanced25 minProNETWORK-040Firewall rule shadowing makes the app port reachable from one segment onlyAn allow rule was added for the correct service, but an earlier broader rule still matches first on another path and blocks the flow unexpectedly.NetworkAdvanced25 minProSECURITY-040New allow rule never takes effectOperators add the expected allow rule for an update feed or admin flow, but traffic still fails because an earlier broader deny or different zone match wins first.SecurityAdvanced25 minProSECURITY-060GuardDuty member onboarding failsThe delegated admin path looks correct, but one child account never enables the detector because organizational guardrails deny the role creation needed by the service.SecurityAdvanced26 minPro