incident-response-trainer
Incident response training · Rule-based scoring
DemoCatalogHistoryDashboard
← Back to catalog
Cloud InfrastructuremediumKMS Key-Policy Cross-Account ExposureHigh asset
Scenario

Encryption-key policy lets another account decrypt protected data

A medium Cloud Infrastructure scenario on KMS Key-Policy Cross-Account Exposure.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.

catalog id · cloud-kms-key-policy-cross-account-exposure

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Scope an over-broad cross-account encryption-key policy
  • Separate what the policy permitted from what was used
MITRE ATT&CKmitre-attack
  • Data from Cloud Storage · CollectionT1530 · TA0009
    PartialMedium confidence

    Trains remediating a key policy that would let an external account decrypt protected data.

MITRE D3FENDmitre-d3fend
  • Resource Access Policy AuditingD3-RAPA
    MappedHigh confidence

    Trains auditing and tightening the over-broad cross-account key policy.

  • User Account PermissionsD3-UAP
    MappedMedium confidence

    Trains scoping the grant to a single named role instead of an account root.

NIST CSF 2.0nist-csf-2
  • Data Security · ProtectPR.DS · PR
    MappedHigh confidence

    Trains the data-security posture that keeps encryption keys from decrypting for outside accounts.

  • Identity Management, Authentication, and Access Control · ProtectPR.AA · PR
    MappedHigh confidence

    Trains least-privilege access control on the key policy.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains using key-usage logs to see what the external account actually decrypted.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains scoping the grant to one role and data class without disabling the key.

CISA Cybersecurity Performance Goalscisa-cpg
  • Secure Sensitive Data2.I
    MappedHigh confidence

    Trains the sensitive-data baseline that keeps protected data non-decryptable by outsiders.

  • Log Collection2.T
    MappedMedium confidence

    Trains preserving key-usage logs that scope the decrypt activity.

CIS Controls v8cis-controls
  • Data ProtectionControl 3
    MappedHigh confidence

    Trains the data-protection control the key policy exercises.

  • Access Control ManagementControl 6
    MappedHigh confidence

    Trains the least-privilege access-control review the key grant requires.