Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-469A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate18 minProSECURITY-147A trust bundle update reaches the API tier, but the sidecar envoy still pins the old bundle hash and east-west mTLS fails only thereCertificate distribution was mostly successful, yet one data-plane component still enforces the previous trust set.SecurityAdvanced18 minProSECURITY-264A Vault policy grants transit encryption while the wrapped response workflow strips the unwrap capability from operators during a failover rehearsalThe crypto permission exists and the operational path to use it is incomplete. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-276An incident quarantine revokes general egress while forensic collection still depends on one artifact upload endpoint during a failover rehearsalContainment is immediate and visibility disappears with it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-240An integrity gate trusts an object-store ETag after transparent recompression changed the real payload identity during a failover rehearsalThe object is present and the hash-like signal no longer represents the original binary content. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProSECURITY-300An OAuth client is disabled while previously issued refresh tokens continue minting delegated access for mobile or desktop clients during a failover rehearsalInteractive sign-in is gone and token lifecycle gaps keep API access alive. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-246An OAuth logout clears browser state while mobile refresh tokens remain active for the same account during a failover rehearsalThe user appears signed out and another client class keeps working as before. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-1246An OIDC login loop continues after a successful callbackOne hostname or browser completes the sign-in flow and another loops forever even though the provider logs a successful callback.SecurityAdvanced18 minProSECURITY-1251An OIDC login loop persists after a successful callbackOne browser or hostname signs in successfully while another loops forever even though the provider logs show success.SecurityAdvanced18 minProSECURITY-106An OPA policy package rename leaves the fallback allow rule active in one cluster after a partial config rolloutMost clusters enforce the new package, but one environment silently drops into the default allow behavior because its bundle path never updated.SecurityAdvanced18 minProCICD-112Cache warming publishes a stale base image to the internal mirror and every subsequent build inherits the vulnerable layerThe dependency warmup stage succeeds, yet later builds are compromised by a mirrored base image that bypassed the freshness policy.CI/CDAdvanced18 minProCICD-122Cosign verification succeeds on the public digest, but deployment pulls from a private mirror that serves a different manifestSupply chain checks pass during build, yet the runtime artifact is not the one that was signed because the mirror rewrites the digest target.CI/CDAdvanced18 minProSECURITY-1208Emergency allowlist fixes the outage but quietly leaves a much broader bypass than intendedA temporary rule restores access, yet it also permits traffic far outside the original blast radius because the exception is too broad.SecurityIntermediate18 minProSECURITY-186Interactive login is disabled while refresh tokens already issued still mint delegated access during a failover rehearsalThe application is gone for humans while API access remains alive through token lifecycle gaps. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-1220Login throttling seems effective but API tokens still bypass itAn app reduces password spray on the browser login page but still sees abusive token requests continue unabated.SecurityIntermediate18 minProSECURITY-1225Login throttling works on the web form but API tokens still bypass itBrowser password spray drops quickly, but token-bearing API abuse continues through another path.SecurityIntermediate18 minProSECURITY-1256OIDC login succeeds at the provider but loops at the appOne login URL works while another hostname for the same app loops forever despite identical provider-side configuration.SecurityAdvanced18 minProSECURITY-1226OIDC login works in one browser but fails in anotherA login flow appears healthy in one hostname path or browser and fails with state or nonce errors in another.SecurityAdvanced18 minProSECURITY-101SAML audience matches, but ACS URL normalization drops the trailing slash and the login flow loops between the app and IdPAuthentication succeeds at the identity provider, yet the application rejects the response because the callback URL comparison is stricter than the team expected.SecurityAdvanced18 minProSECURITY-1202Scanner still sees an exposed admin routeA reverse-proxy rule from community examples protects the obvious admin path. Scanning still finds exposure because a normalized variant resolves through another rule path.SecurityIntermediate18 minPro