Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1282A secret rotation completes in the vault but one service still leaks the old valueA secret is rotated centrally and one service alone continues authenticating with the old value despite a documented hot-reload endpoint.SecurityIntermediate15 minProSECURITY-1300A signed download URL validates in staging but fails in productionSigned file links work in staging and fail only behind the production proxy or CDN path.SecurityIntermediate15 minProSECURITY-1288A signed URL looks valid but file downloads still failDownloads begin failing only after a reverse-proxy or CDN change, even though the signed URL generator code did not change.SecurityIntermediate15 minProSECURITY-1278An app trusts X-Forwarded-Proto from one proxy hop and starts misclassifying secure requestsA reverse proxy or CDN is inserted ahead of an existing app and secure redirect or cookie behavior becomes inconsistent.SecurityIntermediate15 minProSECURITY-134A CASB inline proxy rewrites the downloaded filename, and the DLP hash allowlist no longer matches the approved documentContent is safe, yet the downstream control no longer recognizes it because one enforcement layer changed the file artifact identity.SecurityAdvanced16 minProLINUX-155A chrony source remains reachable through an ACL exception, but NTS validation breaks after the host trust store drops the old rootTime sync traffic still flows, yet secure validation now fails for one trust-specific reason.LinuxAdvanced16 minProSECURITY-122A managed WAF rule override expires at midnight UTC, and the payroll batch starts failing in local business hours the next dayThe temporary exception worked during testing, but time-zone assumptions made its expiry far earlier than operators realized.SecurityAdvanced16 minProSECURITY-1284A new WAF rule blocks only file uploadsA WAF tuning change appears safe until one upload-heavy path begins failing only after a CDN or edge normalization update.SecurityIntermediate16 minProSECURITY-1287A rate limiter reduces abuse in IPv4 logs but an attacker keeps spraying via IPv6 privacy addressesPer-IP rate limiting appears to work and an attack still continues from an address family the dashboards underweight.SecurityAdvanced16 minProCICD-357A reusable workflow signs container images correctly while downstream promotion retags an unsigned digest from a side repository during a staged decommissionSupply-chain controls protect the main path, but a side promotion lane bypasses the signed artifact. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDIntermediate16 minProSECURITY-1267A SameSite cookie setting breaks SSO only on one browser pathA browser-specific SSO failure appears after cookie hardening, while the same app still works through simpler redirect paths.SecurityIntermediate16 minProSECURITY-141A SAML assertion signs correctly, but the audience URI casing changed during the domain move and one service provider rejects only mixed-case callbacksIdentity proof is valid, yet string normalization assumptions differ between the two ends.SecurityAdvanced16 minProSECURITY-1257A secret is rotated but alerts keep firingA team revokes a credential and still sees recurring detections tied to the same historical leak window.SecurityIntermediate16 minProSECURITY-1269A secret leak alert keeps returningA credential is rotated and removed from the main repo, but scanning alerts keep resurfacing from related automation surfaces.SecurityIntermediate16 minProSECURITY-351A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate16 minProSECURITY-1260Password spray continues through rate limitingAn authentication edge still suffers password spraying even after strict per-IP limits were rolled out.SecurityIntermediate16 minProSECURITY-1274Secret scan alerts keep returningA team rotates and removes a credential from the primary repository and still sees recurring alerts tied to the same value.SecurityIntermediate16 minProSECURITY-1212Secret was revoked quickly but scanners keep firingA token leak is revoked and replaced promptly, but secret scanning continues to alert for days.SecurityIntermediate16 minProLINUX-140SSH certificate authentication is configured, but the principals file permissions are too open and the daemon ignores it for security reasonsThe CA trust path is valid, yet certificate login falls back to password prompts because the principal mapping file fails ownership checks.LinuxAdvanced16 minProSECURITY-120The reverse proxy strips HSTS on 304 responses and scanners report an intermittent downgrade riskMost requests include the header, but cache validation paths omit it and some scanners correctly flag the inconsistent transport posture.SecurityAdvanced16 minPro