Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1419A service binding receives a tighter policy and one application tier keeps...A service binding receives a tighter policy and one application tier keeps... focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can persist when applications couple reloads to secret change...SecurityAdvanced14 minProSECURITY-1409A service binding receives the correct policy on first rollout and later...A service binding receives the correct policy on first rollout and later... focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Permission drift can survive policy rollout when pooled connections cache earlie...SecurityAdvanced14 minProSECURITY-1322A Vault policy looks permissive and KV reads still failA service token is updated and later can enumerate secrets but cannot actually read the intended values from Vault.SecurityAdvanced14 minProSECURITY-1401An access proxy protects the user API and one newly split service path is...An access proxy protects the user API and one newly split service path is... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Security regressions often come from route shadowing, not from a mis...SecurityAdvanced14 minProSECURITY-1399An edge remediation list is updated and one POP still serves stale allow...An edge remediation list is updated and one POP still serves stale allow... focuses on incident-response and asks the reader to isolate the key signal in Cloudflare. Edge caching bugs can live in fetch path variants, not only in the visibl...SecurityAdvanced14 minProSECURITY-1416An egress-deny policy passes init checks and later leaks telemetryAn egress-deny policy passes init checks and later leaks telemetry focuses on network-policy and asks the reader to isolate the key signal in cilium. Mesh insertion can change the dataplane attachment point after early policy...SecurityAdvanced14 minProSECURITY-1426An egress-deny policy passes init checks and later leaks telemetryAn egress-deny policy passes init checks and later leaks telemetry focuses on network-policy and asks the reader to isolate the key signal in cilium. Service meshes can change the dataplane attachment point after init-time poli...SecurityAdvanced14 minProSECURITY-1436An egress-deny policy passes init checks and later leaks telemetryAn egress-deny policy passes init checks and later leaks telemetry focuses on network-policy and asks the reader to isolate the key signal in cilium. Service meshes can change dataplane attachment points after init-time policy checks h...SecurityAdvanced14 minProSECURITY-1446An egress-deny policy passes init checks and later leaks telemetryAn egress-deny policy passes init checks and later leaks telemetry focuses on network-policy and asks the reader to isolate the key signal in cilium. Service meshes can change dataplane attachment after init-time checks have already pa...SecurityAdvanced14 minProSECURITY-1406An init container validates egress against an allowlist and production still...An init container validates egress against an allowlist and production... focuses on network-policy and asks the reader to isolate the key signal in cilium. Security validation done too early in pod lifecycle can certify a network sta...SecurityAdvanced14 minProSECURITY-1384An NGINX allowlist protects private APIs and one upstream app becomes...An NGINX allowlist protects private APIs and one upstream app becomes... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Security gaps can live in the ordering between normalization and authorization, no...SecurityAdvanced14 minProSECURITY-1374An NGINX auth_request gateway protects normal methods and one CORS preflight...An NGINX auth_request gateway protects normal methods and one CORS... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Method-specific branches in proxies can bypass security logic even when the main path...SecurityAdvanced14 minProSECURITY-1335An Ubuntu unattended upgrade secures packages and leaves one bastion inaccessibleA hardened bastion receives unattended upgrades and later downstream systems that pin host identity stop trusting it.SecurityIntermediate14 minProSECURITY-1375Cloudflare Access protects the main hostname and an alternate admin listener...Cloudflare Access protects the main hostname and an alternate admin... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Edge access controls are only as complete as the hos...SecurityAdvanced14 minProSECURITY-1379Unattended upgrades complete and the host loses trust in its own workload...Unattended upgrades complete and the host loses trust in its own workload... focuses on Identity And Access and asks the reader to isolate the key signal in ubuntu. Automatic certificate renewal can break local trust pin...SecurityAdvanced14 minProSECURITY-1302Vault KV access works in the UI and fails in automationOperators validate access in the UI and later the service account still gets permission denied on KV reads.SecurityIntermediate14 minProSECURITY-1290A CSP rollout looks correct but one payment popup failsA security hardening rollout passes smoke tests and a third-party popup or embedded checkout later breaks in production.SecurityIntermediate15 minProSECURITY-1298A CSP update allows the vendor script but still breaks checkoutA CSP hardening rollout appears safe and one payment or verification flow still fails in production.SecurityIntermediate15 minProSECURITY-1292A SameSite fix solves desktop login and still breaks mobile webview SSOAn auth hardening change appears successful until mobile app login starts looping while desktop login remains normal.SecurityIntermediate15 minProSECURITY-1272A SameSite hardening change breaks SSO only on one browser flowA cookie hardening rollout leaves some browsers or embedded login flows broken while ordinary browser login still succeeds.SecurityIntermediate15 minPro