Cloud audit logging disabled in a region — detection blind spot
A medium Cloud Infrastructure scenario on Cloud Audit-Logging Gap.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 2 templates in this Track + Difficulty pool.
catalog id · cloud-audit-logging-gap
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Restore a cloud audit-logging blind spot
- Alert on logging changes and corroborate the gap window
- Impair Defenses: Disable or Modify Cloud Logs · Defense EvasionT1562.008 · TA0005PartialMedium confidence
Trains the defender side: remediating a logging gap that reduces detection coverage in a region.
- Network Traffic AnalysisD3-NTAMappedMedium confidence
Trains using remaining flow telemetry to corroborate activity during the gap.
- User Behavior AnalysisD3-UBAPartialLow confidence
Trains looking for unusual activity in the signals that still survive the gap.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains restoring the continuous-monitoring capability the gap removed.
- Adverse Event Analysis · DetectDE.AE · DEMappedMedium confidence
Trains reasoning about what events went unrecorded during the gap.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains scoping the lost window and corroborating from remaining telemetry.
- IR lifecycle phasePreparationMappedHigh confidence
Trains hardening so logging changes are alerted on and centrally retained.
- Log Collection2.TMappedHigh confidence
Trains the log-collection baseline the gap broke and the response restores.
- Detecting Relevant Threats and TTPs3.AMappedMedium confidence
Trains the detection baseline that depends on complete logging.
- Audit Log ManagementControl 8MappedHigh confidence
Trains the audit-log-management control the incident centers on.
- Network Monitoring and DefenseControl 13MappedMedium confidence
Trains the monitoring control that compensates while the trail is restored.