CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-1511An IAM access finding is resolved and a cross-account role still grants accessA retired external account can still assume a role from one region after the primary fix is applied.SecurityAdvanced12 minProSECURITY-1486An OPA bundle rollout succeeds and one deny rule still firesA deny rule that should be gone continues firing after a successful policy bundle rollout.SecurityAdvanced12 minProSECURITY-1475An OPA bundle verifies and stale deny rules persistA policy refactor appears deployed while one deny rule from the old package path still fires in production.SecurityAdvanced12 minProSECURITY-1465An OPA bundle verifies and still serves stale policyOne sidecar still accepts bundles signed with a revoked key even after JWKS rotation.SecurityAdvanced12 minProSECURITY-1362An OpenSearch dashboards login loops after proxy hardeningA reverse proxy is hardened and later users start bouncing between the IdP and dashboards without ever reaching an authenticated session.SecurityIntermediate12 minProSECURITY-1483An OpenSearch snapshot repository stays registered and restores failSnapshot restores fail only after KMS alias rotation while repository verification still passes.SecurityAdvanced12 minProSECURITY-1456An SSH CA principal map becomes too broadSSH certificate access becomes broader than intended after host and role names were standardized.SecurityAdvanced12 minProSECURITY-1365A Cloudflare Access app is protected on 443 and an alternate admin listener remains publicA team puts an app behind Cloudflare Access and later discovers a side-channel admin port on the same origin is still reachable directly.SecurityAdvanced13 minProSECURITY-1356A Fail2ban or CrowdSec pipeline bans the proxy IPA reverse proxy is inserted and automated bans later begin targeting the proxy instead of the actual abusive clients.SecurityIntermediate13 minProSECURITY-1323A Grafana OAuth login works and role sync stays wrongAn IdP cleanup changes claim names and Grafana users later authenticate successfully but lose admin or editor access unexpectedly.SecurityIntermediate13 minProSECURITY-1414A hardened proxy blocks normal admin verbs and one legacy WebDAV endpoint...A hardened proxy blocks normal admin verbs and one legacy WebDAV endpoint... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can escape security controls when named locations do n...SecurityAdvanced13 minProSECURITY-1424A hardened proxy blocks normal admin verbs and one legacy WebDAV path still...A hardened proxy blocks normal admin verbs and one legacy WebDAV path still... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can bypass controls when named locations do not inher...SecurityAdvanced13 minProSECURITY-1444A hardened proxy protects the main admin route and an internal DAV alias still permits writesA proxy looks hardened and a legacy authoring endpoint still accepts writes through one alias path.SecurityAdvanced13 minProSECURITY-1434A hardened proxy protects the main admin route and an internal DAV alias...A hardened proxy protects the main admin route and an internal DAV alias... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can bypass expected auth when named locations do not inhe...SecurityAdvanced13 minProSECURITY-1404A hardened reverse proxy blocks all normal verbs and still leaks file...A hardened reverse proxy blocks all normal verbs and still leaks file... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Security gaps often hide in old HTTP methods that were never exercised during stan...SecurityAdvanced13 minProSECURITY-1328A private registry login is successful and image pulls still return 401A private registry login is successful and image pulls still return 401 focuses on Identity And Access and asks the reader to isolate the key signal in docker. Auth redirects across hosts can fail at cookie scope even when credentials and TLS are co...SecurityIntermediate13 minProSECURITY-1325A WAF managed rule blocks only one mobile clientA WAF ruleset update is followed by selective failures affecting only one legacy mobile client integration.SecurityIntermediate13 minProSECURITY-1394An NGINX auth_request flow protects GET and POST and one WebDAV verb bypasses...An NGINX auth_request flow protects GET and POST and one WebDAV verb... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Rare HTTP verbs often follow older location trees and can bypass newer auth subrequ...SecurityAdvanced13 minProSECURITY-1342An OpenSearch dashboard login loopsA proxy hardening change improves cookie posture and later dashboard users get trapped in a login redirect loop.SecurityIntermediate13 minProSECURITY-1338An OpenSearch Dashboards login loop appearsAn OpenSearch Dashboards login loop appears focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Modern cookie defaults can break older federated flows even when every credential and endpoint is correct.SecurityIntermediate13 minPro