Azure
131 incident problems in Azure environments.
먼저 읽을 가이드
추천 문제
All problems (131)
LINUX-024File exists but service user cannot follow parent directoryFile exists but service user cannot follow parent directory is a hands-on troubleshooting drill. The file permission looks fine, but one directory in the path denies execute permission and breaks access. Azure Linux Service Operations needs to be checked by narrowing scope, re...LinuxBeginner14 minFreeLINUX-038Sudoers drop-in order silently reintroduces password promptsThe main sudoers file looks correct, but a later drop-in overrides the intended NOPASSWD rule and breaks the automation path.LinuxBeginner14 minFreeLINUX-021Cron job runs manually but fails under non-login shellCron job runs manually but fails (404 and Rewrite Mismatch) is a hands-on troubleshooting drill. The command succeeds interactively but breaks in cron because environment setup and path assumptions are missing. Azure Linux Service Operations needs to be checked by narrowing sc...LinuxBeginner15 minFreeNETWORK-021Proxy forwards HTTPS as HTTP after port-based rule rewriteProxy forwards HTTPS as HTTP (Timeouts and Latency) is a hands-on troubleshooting drill. Traffic reaches the proxy, but a port rewrite changes the scheme assumption and breaks the application redirect flow. NGINX Firewall and Proxy Paths needs to be checked by narrowing scope,...NetworkBeginner15 minFreeK8S-078NodeLocal DNSCache keeps using the old upstream after a ConfigMap updateCluster DNS works partially, but one set of nodes still forwards to the retired resolver because the node-local cache path never reloaded the new upstream config.KubernetesIntermediate17 minFreeNETWORK-007A missing ip_forward setting blocks NAT egress after a rebootCovers a kernel network setting problem that a temporary fix resolves but that breaks again after a reboot.NetworkIntermediate22 minFreeNETWORK-020The CDN cache is fine, but a TLS version difference with the origin fails only miss requestsA situation where most requests are cache hits and look fine, but origin communication breaks only in the cache-miss segment.ReviewedNetworkIntermediate24 minProSECURITY-1192Auth hardening breaks API clientsA public hardening checklist changed proxy header behavior. Browser auth appears fine, but downstream API flows now break because the app no longer sees the scheme and host headers it expects.SecurityIntermediate18 minProSECURITY-002An intermediate certificate chain problem that fails only on certain clientsThe latest browsers connect fine, but some clients fail TLS verification because the server does not send the complete certificate chain.SecurityIntermediate21 minProSECURITY-1262A SameSite cookie setting breaks SSO only on one browser pathSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced16 minProSECURITY-1264A secret leak alert keeps returningSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced16 minProSECURITY-156A SIEM dashboard shows the new field names, but the scheduled incident export still queries the old schema and sends empty nightly reportsInteractive analysis is fine, yet one automated reporting path still depends on the legacy field map.SecurityAdvanced16 minProSECURITY-121An OAuth token exchange succeeds, but the resource server clock skew rejects the just-issued JWT as not yet validIdentity is correct, yet token freshness assumptions differ across the two systems.SecurityAdvanced16 minProSECURITY-095SIEM parser update collapses two source IP fields and the threat hunt queries miss half the trafficLogs are arriving, but hunting results look incomplete because the updated parser rewrote field names that saved searches still depend on.SecurityAdvanced16 minProSECURITY-393A break-glass access role bypasses MFA (Auth and Session Failure)A break-glass access role bypasses MFA (Auth and Session Failure) focuses on Identity and Access Management and asks the reader to isolate Auth and Session Failure in Azure. 실무에서는 auth-and-session-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로...SecurityAdvanced17 minProSECURITY-345A federated login trust points at the correct issuer while the downstream application still enforces the old audience or group claim mapping during a staged decommissionAuthentication succeeds at the identity edge and authorization fails where claims are interpreted differently. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.SecurityAdvanced17 minProSECURITY-118A hardware token step-up is required on paper, but the mobile fallback policy silently downgrades privileged actions to SMSAdministrators believe strong authentication protects the action, yet one fallback rule lets the mobile app satisfy the control with a weaker factor.SecurityAdvanced17 minProSECURITY-110A SIEM correlation rule misses an after-hours brute-force chainRaw events arrive, but the analytic never fires because time bucketing no longer aligns with the intended incident window.SecurityAdvanced17 minProSECURITY-125A SIEM suppression for the vulnerability scanner hides real lateral movementNoise reduction worked for one source, but the coarse suppression pattern now covers genuine malicious activity.SecurityAdvanced17 minProSECURITY-102Just-in-time admin approval succeeds, but the bastion PAM cache still enforces the previous group membershipOperators receive the right entitlement in the identity plane, yet the bastion keeps denying access until its local authorization cache expires.SecurityAdvanced17 minPro