Admin/SSH/RDP port open to the internet on a production instance
A easy Cloud Infrastructure scenario on Exposed Cloud Management Port.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 2 templates in this Track + Difficulty pool.
catalog id · cloud-exposed-cloud-management-port
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Restrict internet-exposed management ports
- Confirm no unexpected login before remediating
- External Remote Services · Initial AccessT1133 · TA0001MappedHigh confidence
Trains triage of a management port exposed to the internet and the brute-force pressure it attracts.
- Network Traffic FilteringD3-NTFMappedHigh confidence
Trains restricting the security group so admin ports reach only the bastion or VPN range.
- Network Traffic AnalysisD3-NTAMappedMedium confidence
Trains reviewing access patterns to the exposed service.
- Identity Management, Authentication, and Access Control · ProtectPR.AA · PRMappedHigh confidence
Trains access-control posture that limits who can reach management ports.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection of the exposure and of any successful login from auth logs.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains restricting the security group to known ranges as the containment action.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains separating failed guessing from any successful login in the auth log.
- No Exploitable Services on the Internet2.WMappedHigh confidence
Trains the baseline that keeps management services off the public internet.
- Phishing-Resistant MFA2.EMappedMedium confidence
Trains the MFA baseline that limited impact on the management API.
- Secure Configuration of Enterprise Assets and SoftwareControl 4MappedHigh confidence
Trains the secure-configuration control the exposed rule violated.
- Network Monitoring and DefenseControl 13MappedMedium confidence
Trains the network-monitoring control behind safe ingress restriction.