Encryption-key policy lets another account decrypt protected data
A medium Cloud Infrastructure scenario on KMS Key-Policy Cross-Account Exposure.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.
catalog id · cloud-kms-key-policy-cross-account-exposure
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Scope an over-broad cross-account encryption-key policy
- Separate what the policy permitted from what was used
- Data from Cloud Storage · CollectionT1530 · TA0009PartialMedium confidence
Trains remediating a key policy that would let an external account decrypt protected data.
- Resource Access Policy AuditingD3-RAPAMappedHigh confidence
Trains auditing and tightening the over-broad cross-account key policy.
- User Account PermissionsD3-UAPMappedMedium confidence
Trains scoping the grant to a single named role instead of an account root.
- Data Security · ProtectPR.DS · PRMappedHigh confidence
Trains the data-security posture that keeps encryption keys from decrypting for outside accounts.
- Identity Management, Authentication, and Access Control · ProtectPR.AA · PRMappedHigh confidence
Trains least-privilege access control on the key policy.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains using key-usage logs to see what the external account actually decrypted.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains scoping the grant to one role and data class without disabling the key.
- Secure Sensitive Data2.IMappedHigh confidence
Trains the sensitive-data baseline that keeps protected data non-decryptable by outsiders.
- Log Collection2.TMappedMedium confidence
Trains preserving key-usage logs that scope the decrypt activity.
- Data ProtectionControl 3MappedHigh confidence
Trains the data-protection control the key policy exercises.
- Access Control ManagementControl 6MappedHigh confidence
Trains the least-privilege access-control review the key grant requires.