Certification911 problems· 26 reviewed

CompTIA Security+

911 incident response problems that help with CompTIA Security+ prep.

All problems (911)

SECURITY-204A newly blocked domain remains reachable through stale resolver cache state during a failover rehearsalThe control is correct now while caches preserve yesterday's trust decision. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced17 minProCICD-294A package provenance check validates one tarball while the deploy step consumes a repacked archive from a mirror during a failover rehearsalSupply-chain checks pass on the source artifact, but the runtime path uses a derived archive that was never verified. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDIntermediate17 minProCICD-192An artifact retention job keeps the image and removes the detached attestation during a failover rehearsalThe primary artifact remains available while admission or provenance checks lose the supporting proof they depend on. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDIntermediate17 minProSECURITY-1235Login throttling exists but password spray still succeedsAn authentication surface throttles requests by source IP and still suffers sustained password spraying from clients rotating IPv6 addresses.SecurityIntermediate17 minProSECURITY-1245Password spray continues despite rate limitingAn authentication surface limits requests by source IP and still sees sustained password spraying from rotating IPv6 clients.SecurityIntermediate17 minProSECURITY-1255Password spray continues despite rate limitingAn authentication surface limits by source IP and still suffers sustained password spraying from clients rotating IPv6 addresses.SecurityIntermediate17 minProSECURITY-1250Password spraying continues despite rate limitingAn authentication surface limits by source IP and still suffers sustained password spray from clients rotating IPv6 addresses.SecurityIntermediate17 minProSECURITY-112WebAuthn enrollment succeeds, but the stored rpId still points at the old domain after a production cutoverUsers can register credentials, yet sign-in later fails because the relying party identity was not updated with the new canonical hostname.SecurityAdvanced17 minProSECURITY-258A DNSSEC-signed public zone validates while the internal split-horizon copy still serves unsigned child records during a failover rehearsalExternal trust is healthy and internal trust assumptions no longer match it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProLINUX-541A sudo rule allows the target subcommand (Permission Denied)A sudo rule allows the target subcommand (Permission Denied) focuses on linux-identity-and-access and asks the reader to isolate Permission Denied. 실무에서는 linux-identity-and-access 문제를 볼 때 서비스 로그만 보지 말고 inode, 파일시스템 여유, 포트 점유, systemd 상태, 최근 패키지 변경까지 같이 확인해야 원인을 빨리 좁힐 수 있습니다.LinuxIntermediate18 minProSECURITY-1188Alternate proxy path leaves the admin surface reachable even though the canonical route is protectedSecurity scans still reach an admin path because a second proxy route exposes the same upstream without the expected controls.SecurityIntermediate18 minProSECURITY-117DNSSEC validates at the registrar, but CDS and CDNSKEY automation stopped and the child zone slowly drifts out of syncValidation still passes today, yet the delegation path is aging toward failure because the parent update automation quietly stopped.SecurityAdvanced18 minProSECURITY-1230Rate limiting appears to work but attackers still spray passwordsA team relies on IP-based login throttling and later sees abusive authentication continue from rapidly changing IPv6 clients.SecurityIntermediate18 minProLINUX-601A sudo rule allows the target subcommand (Permission Denied)A sudo rule allows the target subcommand (Permission Denied) focuses on linux-identity-and-access and asks the reader to isolate Permission Denied. 실무에서는 linux-identity-and-access 문제를 볼 때 서비스 로그만 보지 말고 inode, 파일시스템 여유, 포트 점유, systemd 상태, 최근 패키지 변경까지 같이 확인해야 원인을 빨리 좁힐 수 있습니다.LinuxIntermediate19 minProSECURITY-026Security scanner flags admin port exposure only on standby nodeThe active node looks protected, but a standby or failover host still exposes the management service to a wider segment.SecurityIntermediate20 minProSECURITY-017Session cookie becomes insecure after CDN to origin scheme mismatchUsers arrive over HTTPS, but origin headers make the app think the request is plain HTTP and weaken the session cookie flags.SecurityIntermediate20 minProSECURITY-023API key restriction by source IP breaks autoscaled workersThe restriction was safe at one size, but autoscaling introduces new egress addresses that were never added to the policy.SecurityIntermediate21 minProSECURITY-014Container image scan passes base layer but misses runtime package driftContainer image scan passes base layer but misses runtime package drift is a hands-on troubleshooting drill. The registry scan is green, but runtime package installation changes the actual container risk profile after deploy. Incident Response Operations needs to be checked by...SecurityIntermediate21 minProLINUX-720A sudo rule allows the target subcommand (Permission Denied)A sudo rule allows the target subcommand (Permission Denied) focuses on linux-identity-and-access and asks the reader to isolate Permission Denied. 실무에서는 linux-identity-and-access 문제를 볼 때 서비스 로그만 보지 말고 inode, 파일시스템 여유, 포트 점유, systemd 상태, 최근 패키지 변경까지 같이 확인해야 원인을 빨리 좁힐 수 있습니다.LinuxIntermediate22 minProSECURITY-029OAuth callback accepted on web tier but rejected after load balancer hopOAuth callback accepted on web tier but rejected is a hands-on troubleshooting drill. The callback parameters are correct, yet one load balancer rewrite alters the host or scheme expected by validation. Identity and Access Management needs to be checked by narrowing scope, rec...SecurityIntermediate22 minPro