Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1242A rotated secret keeps triggering alertsAn incident response team rotates a secret and later keeps seeing alerts tied to an old downloadable diagnostic archive.SecurityIntermediate17 minProSECURITY-1247A rotated secret keeps triggering alertsAfter a secret rotation, teams still see alerts tied to an old downloadable artifact generated during the incident window.SecurityIntermediate17 minProSECURITY-162A signed identity response is valid while one relying party rejects its audience string under different normalization rules during a failover rehearsalTrust succeeds cryptographically and string semantics still break the session. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced17 minProLINUX-108A sudoers include file loads later and quietly re-enables a broad NOPASSWD rule the team thought it removedPrivilege hardening seems complete, yet one lexical include order detail restores broad administrative access after the next package update.LinuxAdvanced17 minProSECURITY-136A truststore update keeps the same certificate subject but a new public key, and one mTLS client still pins the old key hashEverything looks like the same identity, yet a deeper trust assumption at the client breaks connectivity.SecurityAdvanced17 minProSECURITY-363An app registration is disabled while device code or brokered sessions on managed endpoints still rehydrate delegated access from existing trust state during a staged decommissionNew logins are blocked and managed-session reuse keeps access alive. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced17 minProCICD-153An emergency patch bypasses the normal image scan stage, but admission still expects the scan metadata label and production refuses the deploymentThe fast path skips validation intentionally, yet the runtime guardrail still requires proof that only the normal path produces.CI/CDAdvanced17 minProSECURITY-140An incident isolation rule cuts a host off from attackers and also from the EDR telemetry path, leaving responders blindContainment succeeds, yet investigation quality collapses because the rule removed the team's own visibility channel.SecurityAdvanced17 minProSECURITY-1281An OAuth callback succeeds on the identity provider but the app rejects the...An OAuth callback succeeds on the identity provider but the app rejects the... focuses on Identity And Access and asks the reader to isolate the key signal. OIDC callback bugs can be reverse-proxy identity bugs wearing an auth mask.SecurityAdvanced17 minProSECURITY-145An OAuth consent app was disabled, but an existing refresh token continues minting new access tokensInteractive login is blocked, yet delegated API access survives through a token lifecycle gap.SecurityAdvanced17 minProLINUX-097AppArmor profile loads but one helper binary escapes mediationPrimary commands are constrained, yet a helper path stays unrestricted because the profile pattern never matched the deployed binary location.LinuxAdvanced17 minProCICD-137Build provenance records the merge queue pseudo-ref, but the published tag points elsewhere and auditors cannot reconcile the releaseAll artifacts exist, yet traceability breaks because the build source ref and user-facing release ref diverged.CI/CDAdvanced17 minProLINUX-127Journal forward-secure sealing is enabled, but the verification key was rotated out of sync and log integrity checks now failLogs are still written, yet the trust model behind their integrity no longer validates after a partial key update.LinuxAdvanced17 minProSECURITY-1271JWT verification fails after a planned key rotationAn OIDC issuer rotates signing keys and one downstream service alone begins rejecting valid tokens.SecurityAdvanced17 minProSECURITY-129OCSP stapling is healthy at the edge, but the origin health checker trusts only the leaf and marks the backend down on the renewed chainCustomers see a good certificate path, yet the internal monitor fails because its trust assumption is narrower.SecurityAdvanced17 minProSECURITY-133Passwordless FIDO works on the web portal, but the legacy VPN RADIUS mapping still expects the old UPN suffix and rejects the sessionModern identity succeeds in one channel while a legacy gateway still anchors on an outdated identity format.SecurityAdvanced17 minProK8S-096PodSecurity admission blocks the debug container flow even though the base workload still runsThe app continues serving traffic, but emergency debugging fails because the current security profile denies the ephemeral container path.KubernetesAdvanced17 minProSECURITY-128S3 encryption enforcement is enabled, but a legacy multipart client omits the required KMS context and uploads start failing midstreamThe bucket policy is correct, yet one older client implementation cannot satisfy the newer encryption contract.SecurityAdvanced17 minProSECURITY-130SCIM soft-delete disables the account in the app, but a nested group from a secondary directory sync still grants access through another routeOffboarding looks complete in the primary system, yet effective authorization still arrives from a parallel identity feed.SecurityAdvanced17 minProSECURITY-1217Secret scanning catches the token againA revoked token disappears from the repo tree but scanning keeps flagging downloads or release bundles.SecurityIntermediate17 minPro