Topic33 problems· 1 reviewed

Cloud Security and Governance

33 incident problems about Cloud Security and Governance. Start with the reviewed ones.

All problems (33)

SECURITY-119A CASB session rule blocks downloads in the browser, but the desktop client uses a direct API token path that bypasses the web controlThe browser looks governed, yet data still leaves the tenant because another client channel was never put behind the same session controls.SecurityAdvanced18 minProSECURITY-106An OPA policy package rename leaves the fallback allow rule active in one cluster after a partial config rolloutMost clusters enforce the new package, but one environment silently drops into the default allow behavior because its bundle path never updated.SecurityAdvanced18 minProSECURITY-148A DNS firewall blocks known malicious domains, but the internal resolver still returns stale positive cache answers for one recently blacklisted hostThe policy is correct now, yet the cached resolution path preserves yesterday's trust decision.SecurityAdvanced16 minProSECURITY-137Split-horizon DNS forgot the external TXT record needed for domain ownership, and the SSO cutover never verifies on the public sideInternal testing passes, but the control plane outside the network cannot see the proof it needs.SecurityAdvanced16 minProSECURITY-204A newly blocked domain remains reachable through stale resolver cache state during a failover rehearsalThe control is correct now while caches preserve yesterday's trust decision. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced17 minProSECURITY-258A DNSSEC-signed public zone validates while the internal split-horizon copy still serves unsigned child records during a failover rehearsalExternal trust is healthy and internal trust assumptions no longer match it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-117DNSSEC validates at the registrar, but CDS and CDNSKEY automation stopped and the child zone slowly drifts out of syncValidation still passes today, yet the delegation path is aging toward failure because the parent update automation quietly stopped.SecurityAdvanced18 minProSECURITY-369A DNS sinkhole activates for new queries while one recursive resolver keeps serving stale ECS- or geo-influenced answers from a previous policy epoch during a staged decommissionThe block policy is correct now and resolver memory still reflects the old decision. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityIntermediate16 minProSECURITY-429A DNS sinkhole activates for new queries (DNS Resolution Failure)A DNS sinkhole activates for new queries (DNS Resolution Failure) focuses on cloud-security-and-governance and asks the reader to isolate DNS Resolution Failure. 실무에서는 dns-resolution-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다.SecurityIntermediate17 minProSECURITY-306A DNS-based security control blocks new lookups while stale resolver cache still serves the previous answer for the same host during a failover rehearsalThe control is correct now and one cache layer still trusts yesterday. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minProSECURITY-426A DNS sinkhole activates for new queries (DNS Resolution Failure)A DNS sinkhole activates for new queries (DNS Resolution Failure) focuses on cloud-security-and-governance and asks the reader to isolate DNS Resolution Failure. 실무에서는 dns-resolution-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다.SecurityIntermediate18 minProSECURITY-430A DNS sinkhole activates for new queries (DNS Resolution Failure)A DNS sinkhole activates for new queries (DNS Resolution Failure) focuses on cloud-security-and-governance and asks the reader to isolate DNS Resolution Failure. 실무에서는 dns-resolution-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. In...SecurityIntermediate18 minProSECURITY-490A DNS sinkhole activates for new queries (DNS Resolution Failure)A DNS sinkhole activates for new queries (DNS Resolution Failure) focuses on cloud-security-and-governance and asks the reader to isolate DNS Resolution Failure. 실무에서는 dns-resolution-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. In...SecurityIntermediate19 minPro