Destructive cloud incident — objects deleted and snapshot/backup lifecycle tampered, recovery source must be trusted
A extremely-hard Cloud Infrastructure scenario on Cloud Backup-Tamper Recovery Crisis.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 2 templates in this Track + Difficulty pool.
catalog id · cloud-backup-tamper-recovery-crisis
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Contain active cloud data destruction and backup tampering
- Validate a provably-clean recovery source and harden backups
- Data Destruction · ImpactT1485 · TA0040MappedHigh confidence
Trains response to active bulk deletion of production objects by a compromised automation identity.
- Inhibit System Recovery · ImpactT1490 · TA0040MappedHigh confidence
Trains response to snapshot/backup-lifecycle tampering that undermines recovery integrity.
- User Account ContainmentD3-UACMappedHigh confidence
Trains isolating the compromised automation identity to stop the ongoing destruction.
- Resource Access Policy AuditingD3-RAPAMappedMedium confidence
Trains auditing the tampered lifecycle, retention, and vault-share changes.
- Data Security · ProtectPR.DS · PRMappedHigh confidence
Trains protecting production data and the backups that secure it.
- Incident Recovery Plan Execution · RecoverRC.RP · RCMappedHigh confidence
Trains selecting and validating a provably-clean recovery source when backups are suspect.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains stopping the destruction, isolating the identity, and restoring from a trusted source.
- IR lifecycle phasePost-Incident ActivityMappedMedium confidence
Trains hardening backups to immutable, least-privilege controls so tampering cannot recur.
- System Backups2.OMappedHigh confidence
Trains the backup-integrity baseline the tampering violated and the response restores.
- Secure Sensitive Data2.IMappedMedium confidence
Trains protecting the production data held in the affected storage and backups.
- Data RecoveryControl 11MappedHigh confidence
Trains the data-recovery control behind proving and using a clean recovery source.
- Data ProtectionControl 3MappedMedium confidence
Trains the data-protection control the destructive activity exercises.