Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-116Windows event forwarding over mutual auth works, but the subscription content format drops PowerShell script block logsThe channel is healthy, yet investigation quality degrades because the collector-side format setting strips fields one detection depends on.SecurityAdvanced16 minProSECURITY-142A break-glass account is excluded from conditional access, but the session lifetime policy still revokes it before the maintenance task finishesThe account bypasses the main gate, yet another identity control still constrains the operation.SecurityAdvanced17 minProLINUX-137A bridge netfilter sysctl is set correctly, but unloading and reloading the module resets the value and containers start bypassing the host policyThe host remains configured at rest, yet the live module state changed under the running workload.LinuxAdvanced17 minProSECURITY-114A bucket policy blocks public reads, but the legacy website endpoint still exposes content through an old object ACLThe new policy appears strict, yet one access path bypasses it because object-level permissions were left behind from the static site era.SecurityAdvanced17 minProSECURITY-158A cross-account access analyzer stays green, but a new resource policy grants a service principal wildcard that the analyzer scope does not flag in this org layoutVisibility tooling is present, yet its scope is narrower than the real exposure surface.SecurityAdvanced17 minProSECURITY-103A CSP nonce is generated at the edge, but the application template reuses a stale fragment and browsers block one script bundleThe response headers look correct, yet execution fails because a cached HTML fragment still contains yesterday's nonce value.SecurityAdvanced17 minProSECURITY-155A DLP sensor classifies the document correctly, but a newly compressed archive format bypasses the extraction depth limit and the policy never sees the payloadContent controls are configured, yet packaging format changed the scanner's visibility boundary.SecurityAdvanced17 minProSECURITY-132A GitHub App remains installed after a repository transfer, but the new organization grant was never approved and installation tokens lose repository scopeAutomation still exists, yet the trust boundary around the repo changed in a way the app permissions did not follow.SecurityAdvanced17 minProSECURITY-1291A JWKS rotation is complete but one consumer still failsA token issuer rotates keys and one consumer behind a proxy continues rejecting fresh tokens.SecurityAdvanced17 minProSECURITY-1289A JWT audience check passes in staging but fails in productionAuthentication works end-to-end in staging and fails only in production behind an API gateway performing token exchange or translation.SecurityAdvanced17 minProSECURITY-123A named location in conditional access misses the new SD-WAN egress IP range, and compliant users are suddenly blocked after failoverIdentity posture is good, but network identity changed underneath the access policy.SecurityAdvanced17 minProSECURITY-293A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a maintenance template changeThe chain is globally right and one trust consumer is still anchored to the past. The path looked healthy before the template changed, but one inherited assumption no longer matches the live environment.SecurityAdvanced17 minProSECURITY-297A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a retention policy refreshThe chain is globally right and one trust consumer is still anchored to the past. The operational object still exists somewhere in the system, but the lifecycle policy around its supporting state no longer matches reality.SecurityAdvanced17 minProSECURITY-295A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after an environment identity renameThe chain is globally right and one trust consumer is still anchored to the past. The functional path still exists, but one identity, namespace, or naming assumption still points at the previous environment contract.SecurityAdvanced17 minProSECURITY-144A new KMS grant allows the backup role to decrypt snapshots, but the grant was created in one region and cross-region restore still failsThe permission exists, just not in the control-plane scope the recovery workflow actually uses.SecurityAdvanced17 minProCICD-157A package signing key rotates in the build stage, but the downstream install test still trusts only the old fingerprint and rejects the freshly built repositoryThe package was published correctly, yet the validation environment pins a previous trust root.CI/CDAdvanced17 minProLINUX-141A package update rewrites the PAM stack include order, and MFA still prompts but account validation now happens after the wrong moduleAuthentication appears normal until edge-case users begin failing account checks after successful factors.LinuxAdvanced17 minProSECURITY-1232A revoked credential still keeps surfacing in alertsAfter a credential rotation, scanners continue to alert because an old downloadable debug archive still contains generated metadata from the leak window.SecurityIntermediate17 minProSECURITY-1227A revoked token keeps triggering alertsSecret rotation is complete and scanners still report findings tied to historic debug bundles or retained CI artifacts.SecurityIntermediate17 minProSECURITY-1252A rotated secret keeps alertingAfter incident response, teams still see alerts tied to an older downloadable diagnostic bundle produced during the leak window.SecurityIntermediate17 minPro