CompTIA Security+
911 incident response problems that help with CompTIA Security+ prep.
먼저 읽을 가이드
추천 문제
All problems (911)
CICD-118Secret-scanning allowlist suppresses detection of a real deploy key leak after the repository path pattern changedA known false positive rule is kept too broad, and once the repository layout changes it begins to hide a genuine credential leak in the new path.CI/CDAdvanced17 minProSECURITY-1204Temporary allowlist fixes a false positive but breaks the trust boundary by matching a broader source range than intendedA fast incident fix restores service, yet the allowlist rule now covers far more source space than the team originally intended to trust.SecurityIntermediate17 minProSECURITY-1199Temporary exception in the WAF lives foreverA public WAF tuning pattern recommends a quick allow rule. The exception fixes the incident, then quietly becomes part of the long-term exposure surface.SecurityIntermediate17 minProCICD-148The artifact retention job keeps the container image but deletes the detached attestation blob, and production admission starts blocking the next rolloutBuild and publish succeeded, yet the downstream verifier requires a side artifact that retention policy treated as optional.CI/CDAdvanced17 minProLINUX-129The auditd backlog limit is too small and a privilege escalation burst drops the very exec events the investigation needsThe host stays online, but the audit trail is incomplete because event pressure outran the queue design.LinuxAdvanced17 minProSECURITY-115The OAuth device flow trusted-client list still includes a test app and users can bypass the normal consent reviewThe production app is locked down, yet the device flow stays open because an old trusted client registration survived the environment cleanup.SecurityAdvanced17 minProSECURITY-312A browser isolation or proxy layer protects the main UI while websocket or export paths bypass the protected route entirely during a failover rehearsalThe most visible path is controlled and a lower-visibility path still leaks data or interactivity. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-119A CASB session rule blocks downloads in the browser, but the desktop client uses a direct API token path that bypasses the web controlThe browser looks governed, yet data still leaves the tenant because another client channel was never put behind the same session controls.SecurityAdvanced18 minProSECURITY-222A conditional access policy requires compliant devices while cross-tenant claims are minted by the wrong tenant context during a failover rehearsalThe rule is correct in principle and one federated identity path never carries the expected compliance signal. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-330A container build uses one CA bundle during image creation while the runtime base layer refreshes and trusts a different internal PKI root during a failover rehearsalThe built image and the later-executed image lineage no longer share the same trust store assumptions. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProSECURITY-1241A login loop persists after a successful OIDC callbackOne hostname or browser completes the login flow while another loops indefinitely even though the provider logs show success.SecurityAdvanced18 minProSECURITY-252A mutual TLS path validates client chains while one outbound proxy segment blocks CRL or OCSP fetches during a failover rehearsalThe certificate looks correct and revocation checks quietly fail on one leg of the journey. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-296A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a control-plane upgradeThe chain is globally right and one trust consumer is still anchored to the past. The workload or policy had been stable, but the upgraded control layer now interprets one dependency differently.SecurityAdvanced18 minProSECURITY-294A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service during a failover rehearsalThe chain is globally right and one trust consumer is still anchored to the past. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-298A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service during a rollback rehearsalThe chain is globally right and one trust consumer is still anchored to the past. The steady path hides the problem until the system is asked to move backward through the dependency chain.SecurityAdvanced18 minProLINUX-162A PAM include reorder leaves the visible prompts intact while the account phase now runs under the wrong module stack during a failover rehearsalLogin looks normal until a user path reaches the control phase the new order broke. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxAdvanced18 minProSECURITY-153A PKI automation job renews the leaf certificate first, but the pinned intermediate bundle on one appliance is refreshed only the next day and outbound trust breaks overnightThe chain is valid globally, yet one dependent appliance still pins the previous chain layout.SecurityAdvanced18 minProCICD-270A provenance gate compares Git tags while the published release is built from a detached worktree tarball during a failover rehearsalSource control identity and published artifact identity diverge even though both look plausible in isolation. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProSECURITY-113A renewed intermediate certificate is deployed, but the CRL distribution point still serves the expired issuer chainThe visible cert chain looks modern, yet some clients reject it because revocation infrastructure still references the old issuing hierarchy.SecurityAdvanced18 minProCICD-477A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate18 minPro