IAM role grants wildcard permissions far beyond its workload
A medium Cloud Infrastructure scenario on Over-Permissive IAM Role.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 2 templates in this Track + Difficulty pool.
catalog id · cloud-overpermissive-iam-role
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Least-privilege IAM remediation from observed usage
- Reduce standing blast radius without breaking workloads
- Valid Accounts: Cloud Accounts · Privilege EscalationT1078.004 · TA0004PartialMedium confidence
Trains reasoning about the blast radius a wildcard cloud identity would grant if it were ever compromised.
- User Account PermissionsD3-UAPMappedHigh confidence
Trains scoping the role to least privilege from observed usage.
- Resource Access Policy AuditingD3-RAPAMappedMedium confidence
Trains auditing the policy and trust relationships of the role.
- Identity Management, Authentication, and Access Control · ProtectPR.AA · PRMappedHigh confidence
Trains least-privilege access control for service identities.
- Roles, Responsibilities, and Authorities · GovernGV.RR · GVMappedMedium confidence
Trains governance of standing privilege through periodic access review.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains using audit-log last-used data to derive the minimal needed policy.
- IR lifecycle phasePost-Incident ActivityMappedMedium confidence
Trains periodic access review and guardrails so wildcard roles do not recur.
- Phishing-Resistant MFA2.EPartialLow confidence
Trains the identity-assurance baseline that complements scoping role assumption.
- Detection of Unsuccessful (Automated) Login Attempts2.QMappedMedium confidence
Trains the detection baseline that surfaces misuse of an identity.
- Account ManagementControl 5MappedHigh confidence
Trains the account-management control for over-privileged service identities.
- Access Control ManagementControl 6MappedHigh confidence
Trains the least-privilege access-control review the finding requires.