Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

LINUX-067chrony source priority drift pushes one site out of acceptable Kerberos time skewNTP is technically running everywhere, but one location follows a lower-quality source and drifts just far enough to break time-sensitive authentication.LinuxAdvanced21 minProSECURITY-1206JWT validation fails after key rotationA signing key rotation succeeds for most services but one verifier keeps rejecting valid tokens.SecurityAdvanced21 minProSECURITY-1196JWT validation fails only on one proxy pathA key rotation followed public best practices. One proxy path still rejects tokens because it holds an older JWKS view than the rest of the platform.SecurityAdvanced21 minProSECURITY-011Reverse proxy strips security header needed for SSO callbackThe identity provider finishes correctly, but the application rejects the callback because a forwarded security header never arrives.SecurityIntermediate22 minProLINUX-007TLS verification intermittently failing due to system time driftCovers a system-time problem where the application is fine but certificate validity-time checks drift.LinuxAdvanced23 minProSECURITY-012Token validation passes in app tier but fails in background queueToken validation passes in app tier but fails in background queue is a hands-on troubleshooting drill. A queue consumer uses a different issuer or clock setting and rejects tokens that looked valid at the edge. Identity and Access Management needs to be checked by narrowing sc...SecurityAdvanced26 minProSECURITY-1009A SIEM parser update normalizes timestampsA SIEM parser update normalizes timestamps focuses on Incident Response Operations and asks the reader to isolate Resource Exhaustion in Azure. 실무에서는 resource-exhaustion 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. Incident Response 관점의 점...SecurityIntermediate27 minProSECURITY-018SIEM correlation rule floods on maintenance traffic and hides real alertSIEM correlation rule floods on maintenance traffic and hides real alert is a hands-on troubleshooting drill. A noisy maintenance window generates so many expected signals that the meaningful detection is effectively buried. Incident Response Operations needs to be checked by...SecurityAdvanced27 minProSECURITY-1605A browser isolation policy is updated and one session still allows the wrong extensionOne isolated browser session still allows the wrong extension after a policy update.SecurityIntermediate8 minProSECURITY-1569A CrowdSec parser is updated and one scenario still missesOne CrowdSec scenario misses events after parser updates.SecurityIntermediate8 minProSECURITY-1576A JWKS cache is refreshed and one verifier still rejects new tokensOne verifier still rejects new tokens after JWKS refresh.SecurityIntermediate8 minProSECURITY-1586A JWKS refresh succeeds and one verifier still rejects new tokensOne verifier still rejects new tokens after JWKS refresh.SecurityIntermediate8 minProSECURITY-1596A JWKS refresh succeeds and one verifier still rejects new tokensOne verifier still rejects new tokens after JWKS refresh.SecurityIntermediate8 minProSECURITY-1608A PAM RADIUS realm fix is correct and one bastion still denies usersOne bastion still denies users after a PAM RADIUS realm fix.SecurityIntermediate8 minProSECURITY-1582A Turnstile secret rotates and one worker still verifies with the old keyOne worker still verifies with the old Turnstile key after rotation.SecurityIntermediate8 minProSECURITY-1592A Turnstile secret rotates and one worker still verifies with the old keyOne worker still verifies Turnstile with the old secret after rotation.SecurityIntermediate8 minProSECURITY-1602A Turnstile secret rotation is complete and one page still rejects humansOne page still rejects humans after Turnstile secret rotation.SecurityIntermediate8 minProSECURITY-1572A Turnstile verification secret rotates and one edge still uses the old keyOne edge still verifies Turnstile with the old secret after rotation.SecurityIntermediate8 minProSECURITY-1579An authselect profile updates and one host still denies MFAOne host still denies MFA after authselect profile updates.SecurityIntermediate8 minProSECURITY-1562A Cloudflare Access rule is tightened and one path still bypasses MFAOne app path bypasses MFA after tightening Cloudflare Access.SecurityIntermediate9 minPro