Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1502A WAF managed rule exclusion is added and false positives continueA WAF exclusion suppresses false positives for most APIs and still blocks one JSON-heavy endpoint family.SecurityIntermediate10 minProSECURITY-1464An Elastic detection rule duplicates incidentsIncident count doubles after an ingest pipeline migration even though raw event volume is flat.SecurityIntermediate10 minProSECURITY-1474An Elastic detection stays noisyAlert volume rises after one ingest branch is normalized to ECS while another still uses pre-ECS field mapping.SecurityIntermediate10 minProSECURITY-1459An Elastic rule starts duplicating incidentsIncident count spikes after an ECS cleanup even though the underlying event volume did not change.SecurityIntermediate10 minProSECURITY-1415An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload bugs often come from inode and watcher semantics rather...SecurityIntermediate10 minProSECURITY-1425An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload problems are often inode or watcher issues, not stale data issues.SecurityIntermediate10 minProSECURITY-1435An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload bugs are often inode or watcher issues, not stale data issues.SecurityIntermediate10 minProSECURITY-1445An htpasswd rotation looks applied and the old password still worksAn htpasswd rotation looks applied and the old password still works focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload bugs are often inode or watcher issues, not stale content.SecurityIntermediate10 minProSECURITY-1473A Cloudflare Access policy allows service tokens and still blocks one routeService-token access works for normal paths and fails only when an upstream sends duplicated slashes.SecurityAdvanced11 minProSECURITY-1495A CrowdSec bouncer loads the new decision list and one reverse proxy still blocks healthy clientsHealthy clients remain blocked after CrowdSec decisions are cleaned up behind a reverse proxy chain refactor.SecurityAdvanced11 minProSECURITY-1505A CrowdSec decision list updates and healthy clients still blockHealthy clients remain blocked after decision cleanup behind a reverse proxy chain refactor.SecurityAdvanced11 minProSECURITY-1515A CrowdSec decision list updates and healthy clients still blockHealthy clients remain blocked after decision cleanup behind a reverse proxy chain refactor.SecurityAdvanced11 minProSECURITY-1382A Grafana auth proxy setup works and admin privileges disappearA Grafana auth proxy setup works and admin privileges disappear focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity regressions can come from harmless-looking canonicalization changes like lowercasing...SecurityIntermediate11 minProSECURITY-1392A Grafana team sync still works and one admin loses elevated accessA Grafana team sync still works and one admin loses elevated access focuses on Identity And Access and asks the reader to isolate the key signal in grafana. SSO regressions often come from type changes in claims, not just from missing values.SecurityIntermediate11 minProSECURITY-1488A JWKS rotation completes and one edge still serves stale keysSome clients validate new JWTs while one edge location keeps serving the old compressed JWKS.SecurityAdvanced11 minProSECURITY-1497A JWT issuer rotates keys and one gateway still rejects tokensOne gateway keeps rejecting new JWTs after key rotation while others recover immediately.SecurityAdvanced11 minProSECURITY-1507A JWT issuer rotates keys and one gateway still rejects tokensOne gateway keeps rejecting new JWTs after key rotation while others recover immediately.SecurityAdvanced11 minProSECURITY-1485A Palo Alto URL filtering update is synced and QUIC traffic still bypassesSafe browsing policy works for HTTPS and not for QUIC after an App-ID update.SecurityAdvanced11 minProSECURITY-1385A Prometheus exporter secret is rotated and alerting still uses the old...A Prometheus exporter secret is rotated and alerting still uses the old... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Hot-reload automation can succeed technically while watching the...SecurityIntermediate11 minProSECURITY-1493A Vault token revocation succeeds and an app still authenticatesAn application keeps renewing secrets briefly after its Vault parent token was revoked during an incident response action.SecurityAdvanced11 minPro