CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-032KMS alias resolves correctly but decrypt still fails for the app roleThe application can discover the key alias and reach KMS, yet decrypt operations fail because the key policy and IAM policy do not grant the same effective path.SecurityAdvanced26 minProSECURITY-1187mTLS works on the primary route but fails during failoverA platform verified mTLS on the primary route only. Community discussions suggest the failover path often drifts, and now that path rejects client certs.SecurityAdvanced26 minProSECURITY-006Audit log volume drops after agent restart despite healthy daemon statusThe collector service looks healthy, but filtering or delivery state changes silently reduce security log coverage.SecurityAdvanced27 minProSECURITY-027Egress proxy bypass remains possible through one legacy hostnameMost outbound traffic now uses the secured path, but an overlooked legacy name still resolves around the expected control point.SecurityAdvanced27 minProSECURITY-037Least-privilege refactor breaks cross-account accessA role assumption path worked before the permission cleanup, but third-party or cross-account access now fails because the new trust conditions no longer align with the expected external ID flow.SecurityAdvanced27 minProSECURITY-015Emergency blocklist rule causes asymmetric egress failureEmergency blocklist rule causes asymmetric egress failure is a hands-on troubleshooting drill. A rapid security response closes the obvious path but unexpectedly breaks return traffic for a dependent service flow. Azure Incident Response Operations needs to be checked by narro...SecurityAdvanced28 minProSECURITY-024Incident response snapshot leaks secrets through copied temp filesA manual triage procedure preserves evidence, but the copied bundle accidentally includes secret-bearing temp artifacts.SecurityAdvanced28 minProSECURITY-003WAF rule deployment blocks admin API but misses the real attack pathA hotfix rule stops valid management traffic while the malicious request pattern still finds an unprotected endpoint.SecurityAdvanced28 minProSECURITY-009Mutual TLS works on primary path but fails after east-west failoverCertificates and policies look valid, but the fallback service path presents a different trust context and breaks authentication.SecurityAdvanced29 minProSECURITY-030Threat containment playbook isolates attack but breaks blue team visibilityThe response action succeeds operationally, but telemetry from the isolated segment disappears and hinders further analysis.SecurityAdvanced29 minProSECURITY-021Cloud audit trail disabled in one region after account bootstrapCloud audit trail disabled in one region (Incident Response Operations) is a hands-on troubleshooting drill. Global compliance looks correct, but a newly bootstrapped region silently lacks the expected audit baseline. Incident Response Operations needs to be checked by narrowi...SecurityAdvanced30 minProSECURITY-1599A CrowdSec parser correction lands and one scenario still missesOne CrowdSec scenario still misses after parser corrections.SecurityIntermediate8 minProSECURITY-1589A CrowdSec parser fix lands and one scenario still never firesOne CrowdSec scenario still misses after parser fixes.SecurityIntermediate8 minProSECURITY-1598A PAM radius fallback is fixed and one host still denies usersOne host still denies users after PAM radius fallback fixes.SecurityAdvanced8 minProSECURITY-1564A secret rotation is complete and one workload still reads the old valueOne workload keeps reading the old secret after a successful rotation.SecurityIntermediate8 minProSECURITY-1594An External Secrets fix lands and one app still gets the old payloadOne app still gets the old payload after an External Secrets fix.SecurityIntermediate8 minProSECURITY-1584An External Secrets merge order is fixed and one app still sees the old payloadOne app still sees the old secret payload after merge-order fixes.SecurityIntermediate8 minProSECURITY-1574An External Secrets merge rule is corrected and one workload still builds the old payloadOne workload still assembles the old secret payload after merge-rule cleanup.SecurityIntermediate8 minProSECURITY-1609A CrowdSec parser fix is correct and one decision stream still misses attacksOne decision stream still misses attacks after a CrowdSec parser fix.SecurityAdvanced9 minProSECURITY-1606A JWKS endpoint fix is correct and one verifier still rejects tokensOne verifier still rejects tokens after a JWKS endpoint fix.SecurityAdvanced9 minPro