Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1588A RADIUS failover works and one PAM stack still denies valid usersOne PAM stack still denies valid users during RADIUS failover.SecurityAdvanced9 minProSECURITY-1554A secret rotation completes and one workload still uses the retired valueOne workload keeps using a retired secret after rotation across stores.SecurityIntermediate9 minProSECURITY-1518A SIEM parser accepts the new firewall field and correlation still breaksThreat correlation breaks only for one firewall feed after a vendor format update.SecurityIntermediate9 minProSECURITY-1528A SIEM parser accepts the new firewall field and correlation still breaksThreat correlation breaks only for one firewall feed after a format update.SecurityIntermediate9 minProSECURITY-1508A SIEM parser accepts the new firewall field and threat correlation still breaksThreat correlation breaks only for one firewall feed after a vendor format update.SecurityIntermediate9 minProSECURITY-1498A SIEM pipeline parses the new firewall field and threat correlation still breaksThreat correlation breaks only for one firewall feed after a vendor format update added a new zone field.SecurityIntermediate9 minProSECURITY-1468A token introspection cache keeps denying a restored service accountOne service account remains unauthorized after an emergency rollback restored the client in the IdP.SecurityIntermediate9 minProSECURITY-1478A token introspection rollback restores the client and one service still denies requestsRequests continue failing after app restarts because the negative introspection cache lives in a separate sidecar.SecurityIntermediate9 minProSECURITY-1604An External Secrets template is fixed and one pod still renders the old credentialOne pod still renders the old credential after an External Secrets fix.SecurityAdvanced9 minProSECURITY-1447A fail2ban jail keeps banning the proxy instead of the clientAbuse continues while fail2ban reports bans against the reverse proxy after a structured logging migration.SecurityIntermediate10 minProSECURITY-1407A fail2ban jail keeps unbanning abusive clientsA fail2ban jail keeps unbanning abusive clients focuses on abuse-protection and asks the reader to isolate the key signal in ubuntu. Abuse controls tied to log scraping can fail silently when logging format changes but the jail...SecurityIntermediate10 minProSECURITY-1397A fail2ban jail matches the right event and bans nothingA fail2ban jail matches the right event and bans nothing focuses on incident-response and asks the reader to isolate the key signal in Linux. Security automation often breaks on log-shape migrations that preserve human reada...SecurityIntermediate10 minProSECURITY-1427A fail2ban jail reads failures and stops banning correctlyA fail2ban jail reads failures and stops banning correctly focuses on abuse-protection and asks the reader to isolate the key signal in ubuntu. Structured log migrations can change which IP a parser captures even when the event itself i...SecurityIntermediate10 minProSECURITY-1417A fail2ban jail reads login failures correctly and stops banningA fail2ban jail reads login failures correctly and stops banning focuses on abuse-protection and asks the reader to isolate the key signal in ubuntu. Structured logging migrations can preserve the event and still change which IP field the...SecurityIntermediate10 minProSECURITY-1437A fail2ban jail still reads failures and stops banning correctlyAbuse spikes continue while fail2ban reports bans against the proxy after a move to structured logs.SecurityIntermediate10 minProSECURITY-1387A fail2ban rule triggers on the right log lines and never blocks the clientA fail2ban rule triggers on the right log lines and never blocks the client focuses on incident-response and asks the reader to isolate the key signal in Linux. Detection and enforcement can drift apart when one consumes par...SecurityIntermediate10 minProSECURITY-1568A PAM radius failover recovers and one host still rejects valid usersOne host rejects valid users only on radius failover paths.SecurityAdvanced10 minProSECURITY-1512A WAF exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON route family.SecurityIntermediate10 minProSECURITY-1522A WAF exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON route family.SecurityIntermediate10 minProSECURITY-1492A WAF managed rule exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON-heavy endpoint family.SecurityIntermediate10 minPro