Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1186Secrets scanner flags a revoked key and the team cannot tell if the exposure is still realA pipeline finds a leaked credential pattern, but responders must determine whether the secret is active, historical, or already revoked before escalating incorrectly.SecurityIntermediate18 minProSECURITY-1197Security scan reports a public admin routeA route looks protected in manual testing, yet a scan still reaches the admin path because one redirect or normalized path bypasses the auth requirement.SecurityIntermediate18 minProCICD-127The release pipeline signs the SBOM for the original image digest, but a last-minute rebuild produces a new digest that goes out unsignedEvery compliance report points at a valid attestation, just not for the image that actually ships.CI/CDAdvanced18 minProSECURITY-126Vault dynamic database credentials expire before a long-running transaction completes, and the application reports random commit failuresSecrets are rotated safely, but workload runtime exceeds the lease model the security design assumed.SecurityAdvanced18 minProCICD-228A deploy pipeline signs the container image but not the values bundle that actually changes runtime behavior during a failover rehearsalSupply-chain checks pass for the binary artifact while the configuration artifact remains unsigned and mutable. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-476A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate19 minProCICD-478A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate19 minProSECURITY-198An updated trust bundle reaches the app while the sidecar or proxy path still pins the previous set during a failover rehearsalThe main process trusts the new chain and an adjacent component still rejects it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced19 minProSECURITY-1194Basic auth on one route hides that the file-upload path uses a different location blockThe visible admin page is protected, but the upload path still reaches the backend unauthenticated because it matches another location rule.SecurityIntermediate19 minProSECURITY-336Containment revokes general egress while one evidence collection or telemetry upload endpoint was still needed for the investigation during a failover rehearsalThe isolation step works and responders lose the path that would have made the incident explainable. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced19 minProSECURITY-1182Fail2ban blocks trusted health checksA public Fail2ban recipe is copied into a reverse-proxy deployment and legitimate checks start getting banned as if they were attacks.SecurityIntermediate19 minProLINUX-078nftables set refresh leaves stale IP entriesThe firewall update appears to run, but some stale members stay active because the atomic update path failed halfway and the old set was never swapped cleanly.LinuxAdvanced19 minProK8S-092Projected CA bundle on one namespace lags and only that team's jobs fail outbound TLS validationCluster TLS trust is mostly healthy, but one namespace still mounts an older CA bundle and its jobs reject the new upstream certificate path.KubernetesAdvanced19 minProSECURITY-1190Scanner reports the upload path is openA basic-auth recipe from community forums was added to NGINX. The visible admin UI is protected, but an adjacent upload path still reaches the backend unauthenticated.SecurityIntermediate19 minProSECURITY-008Secrets scanner flags a rotated key that is already revokedThe alert is technically correct for the repository history, but the key is no longer active and the response path is unclear.SecurityIntermediate19 minProLINUX-088SELinux policy module loads successfully but a file transition rule never matches the deployed pathThe custom policy is present, yet denials continue because the actual path used in deployment does not trigger the transition rule the author expected.LinuxAdvanced19 minProSECURITY-1209SIEM pipeline is healthy but one event class disappearsA forwarder still ships logs, but investigation data is missing because a parser drops one event type after a field change.SecurityIntermediate19 minProCICD-536A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate20 minProSECURITY-589A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate20 minProSECURITY-649A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate21 minPro