Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1503A Vault token revocation succeeds and the app still authenticatesAn application keeps renewing secrets briefly after its Vault parent token was revoked.SecurityAdvanced11 minProSECURITY-1513A Vault token revocation succeeds and the app still authenticatesAn application keeps renewing secrets briefly after its Vault parent token is revoked.SecurityAdvanced11 minProSECURITY-1523A Vault token revocation succeeds and the app still authenticatesAn application keeps renewing secrets briefly after Vault revocation.SecurityAdvanced11 minProSECURITY-1405An htpasswd secret is updated and the ingress still accepts the old passwordAn htpasswd secret is updated and the ingress still accepts the old password focuses on reload-behavior and asks the reader to isolate the key signal in Kubernetes. Secret reload problems can come from normalization logic in th...SecurityIntermediate11 minProSECURITY-1366A ban pipeline targets the proxy instead of the attackerA reverse proxy is inserted or reconfigured and automated bans later start punishing the proxy instead of abusive clients.SecurityIntermediate12 minProSECURITY-1454A Cloudflare Access service token works for normal API calls and fails on one...A Cloudflare Access service token works for normal API calls and fails on... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Upgrade paths often use different rule branches than ordinary HTTP re...SecurityAdvanced12 minProSECURITY-1469A JWKS rotation succeeds and one edge cache still serves the old key setSome clients validate new JWTs while one region keeps seeing the old JWKS after rotation.SecurityAdvanced12 minProSECURITY-1479A JWKS rotation succeeds and one edge still serves stale keysSome clients validate new JWTs while one edge path keeps serving the old compressed JWKS document.SecurityAdvanced12 minProSECURITY-1481A Keycloak login works and one app still loopsOIDC login loops only for one app after proxy host rewrites were centralized.SecurityAdvanced12 minProSECURITY-1480A secret rotation succeeds and RDS auth still failsDatabase logins fail intermittently after secrets rotation while some requests still succeed on long-lived workers.SecurityAdvanced12 minProSECURITY-1470A secrets rotation completes and database auth still failsDatabase auth fails intermittently after a secrets rotation while some workers continue to function.SecurityAdvanced12 minProSECURITY-1461A Vault Agent rotates the certificate and one JVM still presents the old chainAn mTLS client keeps presenting the retired chain after Vault Agent rotates the file-backed certificate.SecurityAdvanced12 minProSECURITY-1471A Vault Agent rotates the leaf cert and the app still presents the old chainA restarted JVM still serves the old chain when Vault Agent rotates secrets just after process bootstrap.SecurityAdvanced12 minProSECURITY-1452A Vault Transit key rotates and one app tier still rejects JWE tokensEncrypted tokens fail only in one app tier after Transit key rotation while decryption still works elsewhere.SecurityAdvanced12 minProSECURITY-1482An Elastic ingest pipeline update lands and one shard still rejects documentsDocument rejection persists only on one shard after an ingest pipeline and template refactor.SecurityAdvanced12 minProSECURITY-1373An Elastic logging sidecar reconnects (elastic-sidecar-mounted-new-secret-but-kept-old-key-in-env-file)An Elastic logging sidecar reconnects (elastic-sidecar-mounted-new-secret-but... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Projected secret updates do not guarantee the process r...SecurityIntermediate12 minProSECURITY-1477An HA firewall pair shares sessions and URL filtering still divergesThe same URL is blocked on one HA node and allowed on the other during an update window.SecurityAdvanced12 minProSECURITY-1467An HA URL filtering pair divergesA security policy appears inconsistent across the HA pair during a category database refresh window.SecurityAdvanced12 minProSECURITY-1491An IAM access analyzer finding is resolved and a cross-account role still grants accessA cross-account role remains reachable from a retired account even after the primary stack set shows the fix applied.SecurityAdvanced12 minProSECURITY-1501An IAM access finding is resolved and a cross-account role still grants accessA retired external account can still assume a role from one region after the main fix is applied.SecurityAdvanced12 minPro