CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
SECURITY-1352An OpenSearch SSO redirect loop appears after proxy hardeningA reverse proxy is hardened and later users become trapped in a dashboard login loop even though the identity provider is healthy.SecurityIntermediate13 minProSECURITY-1316An SSH CA rollout signs host certificates correctly and engineers still get...An SSH CA rollout signs host certificates correctly and engineers still get... focuses on Identity And Access and asks the reader to isolate the key signal in Linux. SSH CA incidents often hide in stale host cert issuance rather t...SecurityIntermediate13 minProSECURITY-1396A Cilium egress deny policy appears tight and one init container still...A Cilium egress deny policy appears tight and one init container still... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Short-lived container phases can expose timing windows that st...SecurityAdvanced14 minProSECURITY-1367A Cilium FQDN policy allows the configured hostname and still blocks trafficA service mesh is enabled and only name-based egress policy begins failing for one dependency path.SecurityAdvanced14 minProSECURITY-1355A Cloudflare Access app is protected on 443 and an alternate admin port...A Cloudflare Access app is protected on 443 and an alternate admin port... focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cloudflare. Zero Trust at the main hostname does not automatically...SecurityAdvanced14 minProSECURITY-1391A Cloudflare Access application protects the dashboard and one API path stays...A Cloudflare Access application protects the dashboard and one API path... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Machine-auth exceptions can unintentionally shadow user-facing policy when hos...SecurityAdvanced14 minProSECURITY-1326A GitHub package publish from Dependabot failsA GitHub package publish from Dependabot fails focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Different GitHub event types can carry meaningfully different token capabilities even inside one repos...SecurityAdvanced14 minProSECURITY-1351A Grafana login succeeds and team access disappearsAn SSO schema update lands and later Grafana users can log in but lose the permissions tied to their old team claim mapping.SecurityAdvanced14 minProSECURITY-1361A Grafana SSO login succeeds and folders vanishAn IdP schema update rolls out and later Grafana users can log in but lose access to the teams and folders they previously owned.SecurityAdvanced14 minProSECURITY-1403A JWKS rotation finishes cleanly and token verification still fails on one...A JWKS rotation finishes cleanly and token verification still fails on one... focuses on Cache Control and asks the reader to isolate the key signal in NGINX. Key rotation failures often come from stale cache behavior, not from bad tokens...SecurityAdvanced14 minProSECURITY-1413A JWKS rotation succeeds and one edge still rejects valid tokensA JWKS rotation succeeds and one edge still rejects valid tokens focuses on Cache Control and asks the reader to isolate the key signal in NGINX. JWKS cache bugs can be path-scoped even when the issuer hostname is shared across applications.SecurityAdvanced14 minProSECURITY-1423A JWKS rotation succeeds and one edge tier still rejects valid tokensA JWKS rotation succeeds and one edge tier still rejects valid tokens focuses on Cache Control and asks the reader to isolate the key signal in NGINX. JWKS cache bugs can hide at the path level even when the issuer hostname is shared.SecurityAdvanced14 minProSECURITY-1433A JWKS rotation succeeds and one edge tier still rejects valid tokensA JWKS rotation succeeds and one edge tier still rejects valid tokens focuses on Cache Control and asks the reader to isolate the key signal in NGINX. JWKS cache issues can hide at the path level even when the issuer hostname is shared.SecurityAdvanced14 minProSECURITY-1443A JWKS rotation succeeds and one edge tier still rejects valid tokensOne application starts failing token validation after a key rotation while another under the same issuer still works.SecurityAdvanced14 minProSECURITY-1346A Netgate and CrowdSec style ban pipeline blocks the proxy addressA Netgate and CrowdSec style ban pipeline blocks the proxy address focuses on incident-response and asks the reader to isolate the key signal in NGINX. Source-IP based security automation breaks quickly when proxy trust boundaries...SecurityIntermediate14 minProSECURITY-1337A Prometheus alert route looks normal and a security incident still pages the...A Prometheus alert route looks normal and a security incident still pages... focuses on Deployment Governance and asks the reader to isolate the key signal in grafana. Routing errors in alerting often begin with label loss earlier in the p...SecurityAdvanced14 minProSECURITY-1389A remediation feed is healthy and one region ignores itA remediation feed is healthy and one region ignores it focuses on incident-response and asks the reader to isolate the key signal in Cloudflare. Security feed drift can come from edge cache key design, not from the upstream deci...SecurityAdvanced14 minProSECURITY-1429A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when apps only invalidate p...SecurityAdvanced14 minProSECURITY-1439A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when pools refresh on...SecurityAdvanced14 minProSECURITY-1449A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when pools refresh on...SecurityAdvanced14 minPro