Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1430A Vault database secret rotates cleanly and one app tier still rejects loginsA Vault database secret rotates cleanly and one app tier still rejects logins focuses on credential-rotation and asks the reader to isolate the key signal in hashicorp. Generated secret regressions can come from application-side...SecurityIntermediate11 minProSECURITY-1440A Vault database secret rotates cleanly and one app tier still rejects loginsA Vault database secret rotates cleanly and one app tier still rejects logins focuses on credential-rotation and asks the reader to isolate the key signal in hashicorp. Generated secret regressions often come from application-side par...SecurityIntermediate11 minProSECURITY-1450A Vault database secret rotates cleanly and one app tier still rejects loginsA Vault plugin update lands and only one application tier loses database access while others continue to work.SecurityIntermediate11 minProSECURITY-1420A Vault database secret rotates successfully and one app tier still rejects...A Vault database secret rotates successfully and one app tier still rejects... focuses on credential-rotation and asks the reader to isolate the key signal in hashicorp. Generated secret regressions often come from client-side p...SecurityIntermediate11 minProSECURITY-1400A Vault dynamic DB credential works and one app still rejects itDynamic credentials are rolled out and one application alone starts rejecting them despite the DB and Vault role being correct.SecurityIntermediate11 minProSECURITY-1410A Vault-backed application rotates database credentials and one app tier...A Vault-backed application rotates database credentials and one app tier... focuses on credential-rotation and asks the reader to isolate the key signal in hashicorp. Credential rotation failures can come from application-side assumption...SecurityIntermediate11 minProSECURITY-1390A Vault-issued short-lived database credential works in staging and fails in...A Vault-issued short-lived database credential works in staging and fails... focuses on Identity And Access and asks the reader to isolate the key signal in hashicorp. Dynamic secret adoption can fail on local validation code that was wri...SecurityIntermediate11 minProSECURITY-1412An RBAC bridge maps admin groups correctly in staging and drops them in...An RBAC bridge maps admin groups correctly in staging and drops them in... focuses on Identity And Access and asks the reader to isolate the key signal in okta. RBAC drift across environments often comes from parser assumptions abo...SecurityIntermediate11 minProSECURITY-1422An RBAC bridge maps admin groups in staging and drops them in productionAn RBAC bridge maps admin groups in staging and drops them in production focuses on Identity And Access and asks the reader to isolate the key signal in okta. RBAC drift is often caused by claim-shape changes, not by missing groups.SecurityIntermediate11 minProSECURITY-1432An RBAC bridge maps admin groups in staging and drops them in productionAn RBAC bridge maps admin groups in staging and drops them in production focuses on Identity And Access and asks the reader to isolate the key signal in okta. RBAC drift across environments is often a claim-shape problem rather than a m...SecurityIntermediate11 minProSECURITY-1442An RBAC bridge maps admin groups in staging and drops them in productionAn RBAC bridge maps admin groups in staging and drops them in production focuses on Identity And Access and asks the reader to isolate the key signal in okta. RBAC drift across environments is often a claim-shape problem.SecurityIntermediate11 minProSECURITY-1378A Prometheus alert reaches Alertmanager and never pages the right teamAn alerting pipeline cleanup merges relabel rules and later some incidents stop paging the owning team even though alerts still fire.SecurityIntermediate12 minProSECURITY-1348A Prometheus alert should page security and routes to the platform teamAn alerting cleanup lands and later security-sensitive incidents begin paging the default platform rotation instead of the intended responders.SecurityIntermediate12 minProSECURITY-1368A Prometheus security alert pages the platform teamAn alerting cleanup lands and later security incidents page the default platform rotation instead of the intended responders.SecurityIntermediate12 minProSECURITY-1358A Prometheus security alert should route to the security team and lands on...A Prometheus security alert should route to the security team and lands on... focuses on Deployment Governance and asks the reader to isolate the key signal in grafana. Alert routing failures often start upstream in relabel logic, n...SecurityIntermediate12 minProSECURITY-1364An auth_request chain protects the browser UI and one API path bypasses policyA reverse proxy centralizes auth and later only API clients find a path that avoids the expected policy check.SecurityIntermediate12 minProSECURITY-1354An NGINX auth_request policy protects the browser UI and one API route...An NGINX auth_request policy protects the browser UI and one API route... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Auth bypasses often hide in alternate method paths the happy-path browser flow never...SecurityIntermediate12 minProSECURITY-1402An RBAC mapper reads the IdP claim and drops every admin groupAn RBAC mapper reads the IdP claim and drops every admin group focuses on Identity And Access and asks the reader to isolate the key signal in okta. Authorization bugs often come from token shape drift rather than token content disapp...SecurityIntermediate12 minProSECURITY-1344An NGINX auth_request chain protects the UI and one API path still bypasses policyA reverse proxy centralizes auth and later only API clients or browser preflight flows can reach one path without the expected policy check.SecurityIntermediate13 minProSECURITY-1333An NGINX auth_request chain works for browsers and fails for API clientsAn NGINX auth_request chain works for browsers and fails for API clients focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Authentication success at the edge does not preserve every authorization s...SecurityIntermediate13 minPro