CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-059Conditional access blocks the break-glass admin path during a device compliance incidentThe stronger policy makes sense normally, but the emergency access route now fails because it was never carved out from the same device compliance requirements.SecurityIntermediate18 minFreeSECURITY-036IMDSv1 remains reachable on a standby node after hardening rolloutPrimary instances were hardened correctly, but a rarely used standby or replacement path still exposes the older metadata service behavior.SecurityIntermediate18 minFreeSECURITY-073mTLS client authentication failsThe certificate is valid and trusted, but client auth still fails because the service enforces a SAN type that the issued cert never included.SecurityIntermediate18 minFreeSECURITY-067Certificate transparency alert points to a legacy SAN certificate still trusted by one proxy pathThe newly issued certificate is intentional, but one forgotten proxy still trusts the older SAN chain and continues to present the unexpected path.SecurityIntermediate19 minFreeNETWORK-057Dynamic ARP inspection drops a host after a static IP move without updated bindingsLayer2 connectivity looks normal, but one endpoint stops talking because the protection policy still trusts the old DHCP or ARP binding state.NetworkIntermediate19 minFreeSECURITY-010Password policy update breaks automation account loginA stronger policy is applied broadly, but one unattended account still uses the old credential pattern and starts failing.SecurityBeginner13 minFreeLINUX-084sudo NOPASSWD rule is present but a later group rule still forces password promptsThe expected privilege rule exists, but one broader matching policy lower in the evaluation path overrides the operator's assumption about effective behavior.LinuxIntermediate13 minFreeSECURITY-131A CSP report-only endpoint loops back through the same proxy path and turns a small XSS burst into an internal traffic floodDetection remains enabled, but the reporting path amplifies rather than observes the incident.SecurityIntermediate15 minFreeSECURITY-007Fail2ban blocks internal health checks after noisy auth failuresA brute-force defense rule works, but its source grouping catches internal monitoring traffic by mistake.SecurityBeginner15 minFreeLINUX-086sshd Match block for a bastion subnet disables agent forwarding on one host class onlySSH works broadly, but a specific bastion path behaves differently because a later Match clause quietly changes capabilities for one source range.LinuxIntermediate15 minFreeLINUX-066SELinux blocks the new content rootPermissions and ownership look correct, but the service still gets denied because the moved directory kept the wrong security context.LinuxIntermediate16 minFreeLINUX-094SELinux context is correct on the binary but the parent directory type still blocks traversalThe executable label looks valid, yet access fails because one parent directory retains a context that denies the path traversal required to reach the file.LinuxIntermediate16 minFreeCICD-108Artifact retention removes the SBOM before the security gate runs and attestation verification reports a missing dependency inventoryBuilds finish successfully, but the delayed security job cannot verify compliance because the artifact policy pruned the required software bill of materials too early.CI/CDIntermediate17 minFreeSECURITY-270Browser isolation covers the main admin page while websocket upgrades to the same host bypass the isolated route during a failover rehearsalThe most visible path is protected and a less visible interactive path is not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-035Identity provider session expires before a long-running admin workflow finishesThe user signs in successfully and starts a privileged operation, but the background confirmation step fails because the IdP session duration is shorter than the workflow window.SecurityBeginner17 minFreeLINUX-070SSSD cache preserves deleted group membership and sudo access lingers after offboardingThe identity source is already updated, but one host still grants privileged access because its local cache did not expire when the account changed.LinuxIntermediate17 minFreeSECURITY-061SAML login fails after an IdP migrationThe IdP is reachable and the assertion is signed, but the application still rejects login because the expected identity field changed during the migration.SecurityIntermediate18 minFreeSECURITY-054SIEM parser timezone drift shifts the incident timeline by several hoursThe raw logs are present, but correlation and response decisions go wrong because one pipeline normalizes timestamps differently from the rest of the stack.SecurityIntermediate19 minFreeSECURITY-028CSP header blocks internal admin tool script after hardeningCSP header blocks internal admin tool script is a hands-on troubleshooting drill. A new browser security policy helps overall, but one internal tool script source was never added and breaks the page. Azure Identity and Access Management needs to be checked by narrowing scope,...SecurityBeginner13 minFreeSECURITY-019Nginx basic auth protects one path but leaves upload endpoint openNginx basic auth protects one path but leaves upload endpoint open is a hands-on troubleshooting drill. The visible admin page is protected, but an adjacent upload route bypasses the same security control. NGINX Identity and Access Management needs to be checked by narrowing s...SecurityBeginner13 minFree