Backup snapshot shared publicly — recovery + data-exposure incident
A hard Cloud Infrastructure scenario on Exposed Cloud Backup Snapshot.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 2 templates in this Track + Difficulty pool.
catalog id · cloud-exposed-cloud-backup-snapshot
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Contain a publicly-shared backup snapshot
- Validate recovery integrity and harden sharing controls
- Transfer Data to Cloud Account · ExfiltrationT1537 · TA0010MappedHigh confidence
Trains response to a backup snapshot shared publicly or to an unknown account.
- Resource Access Policy AuditingD3-RAPAMappedHigh confidence
Trains auditing and removing the snapshot share and checking the encryption key policy.
- User Account PermissionsD3-UAPMappedMedium confidence
Trains scoping the backup-automation identity that set the share.
- Data Security · ProtectPR.DS · PRMappedHigh confidence
Trains the data-security posture for backups holding production data.
- Incident Recovery Plan Execution · RecoverRC.RP · RCMappedHigh confidence
Trains validating a clean, trustworthy recovery source after the exposure.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains making the snapshot private and confirming recovery integrity.
- IR lifecycle phasePost-Incident ActivityMappedMedium confidence
Trains hardening snapshot-sharing controls so the automation bug cannot recur.
- System Backups2.OMappedHigh confidence
Trains the backup-protection baseline the exposed snapshot violated.
- Secure Sensitive Data2.IMappedMedium confidence
Trains the sensitive-data baseline for production data inside backups.
- Data ProtectionControl 3MappedHigh confidence
Trains the data-protection control the snapshot exposure exercises.
- Data RecoveryControl 11MappedHigh confidence
Trains the data-recovery control behind validating a clean recovery source.