Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-1307An OIDC mobile deep link works in test and fails in productionA mobile auth flow works in staging and later fails only in production after app-registration values were copied manually.SecurityIntermediate13 minProSECURITY-1286A browser session survives logout on one deviceSome devices keep reentering the app after logout while others behave normally, especially when traversing one CDN path.SecurityIntermediate14 minProSECURITY-1319A Docker registry login succeeds and image pulls still return 401A private registry sits behind a proxy and operators can log in successfully but certain pull paths still bounce with 401 errors.SecurityIntermediate14 minProSECURITY-1296A logout endpoint clears the main session cookie but the user still appears logged inUsers keep reentering the app after logout on one route while the primary session cookie clearly disappears.SecurityIntermediate14 minProSECURITY-1314A Palo Alto decryption bypass rule seems present and one SaaS login still...A Palo Alto decryption bypass rule seems present and one SaaS login still... focuses on Identity And Access and asks the reader to isolate the key signal in palo-alto. Federated login flows often traverse more TLS identities than the visible...SecurityIntermediate14 minProSECURITY-1306A SAML logout works on the main domain and loops on the callback pathA reverse proxy serves the same app successfully until logout or ACS validation starts looping under one path.SecurityIntermediate14 minProSECURITY-1280A scanner still finds a revoked secretAn incident response rotation is complete and secret alerts keep resurfacing from old downloadable support outputs.SecurityIntermediate14 minProSECURITY-1294A secret was rotated everywhere but scanners keep finding itSecret rotation is complete and alerts continue from old CI logs or artifacts tied to a previous variable name.SecurityIntermediate14 minProSECURITY-1276A nonce cookie exists but the app still loops on loginOne sign-in URL works and another alias for the same app loops forever despite matching provider configuration.SecurityIntermediate15 minProLINUX-363A sudo rule allows the target subcommand while PAM account restrictions on time or host still block the noninteractive invocation during a staged decommissionPath authorization is correct, but session policy still denies execution. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.LinuxIntermediate15 minProLINUX-146An rsyslog ruleset drops duplicate messages aggressively, and a brute-force pattern disappearsThe host is quieter, but the deduplication logic removed meaningful repetition that analysts rely on.LinuxIntermediate15 minProCICD-134A dependency proxy serves a cached package manifest after the source package was revoked, and downstream builds keep resolving the unsafe versionUpstream fixed the issue, but the local acceleration layer preserved the vulnerable metadata view.CI/CDIntermediate16 minProSECURITY-148A DNS firewall blocks known malicious domains, but the internal resolver still returns stale positive cache answers for one recently blacklisted hostThe policy is correct now, yet the cached resolution path preserves yesterday's trust decision.SecurityAdvanced16 minProCICD-144A merge queue rebases the branch after tests pass, but the artifact fingerprint still reflects the pre-rebase commit and provenance checks reject the releaseThe code intent did not change much, yet artifact identity no longer matches the merge result the repository now points at.CI/CDIntermediate16 minProSECURITY-151A passkey login works on the primary domain, but a support subdomain still advertises the old RP ID and users cannot recover sessions therePasswordless auth is partially deployed, leaving one operational path outside the trust boundary.SecurityAdvanced16 minProLINUX-240A sudo rule matches a command path before alternatives flips the symlink to a new binary during a failover rehearsalPrivilege logic was tied to one pathname and the real executable moved beneath it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxIntermediate16 minProLINUX-300A sudoers include grants the right command path while the shell wrapper now invokes a different binary via env indirection during a failover rehearsalThe human command looks the same and the executed path is not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxIntermediate16 minProSECURITY-127An SSH CA signs the right principal, but a restrictive source-address critical option excludes the bastion's NAT rangeCertificate auth looks correct until network translation changes the apparent client source.SecurityAdvanced16 minProLINUX-192Noise suppression removes the repeated signal analysts rely on for brute-force detection during a failover rehearsalThe logs are cleaner and the incident pattern disappears with the noise. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxIntermediate16 minProSECURITY-137Split-horizon DNS forgot the external TXT record needed for domain ownership, and the SSO cutover never verifies on the public sideInternal testing passes, but the control plane outside the network cannot see the proof it needs.SecurityAdvanced16 minPro