Public object-storage bucket exposed — customer files world-readable
A easy Cloud Infrastructure scenario on Public Object-Storage Exposure.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 2 templates in this Track + Difficulty pool.
catalog id · cloud-public-object-storage-exposure
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Reduce public exposure of cloud storage
- Preserve access-log evidence and scope blast radius
- Data from Cloud Storage · CollectionT1530 · TA0009MappedHigh confidence
Trains defensive triage when a storage bucket is left publicly readable and customer data could be collected.
- Resource Access Policy AuditingD3-RAPAMappedHigh confidence
Trains auditing and correcting the bucket access policy that exposed the data.
- User Account PermissionsD3-UAPMappedMedium confidence
Trains scoping the deploy service account that set the public policy.
- Data Security · ProtectPR.DS · PRMappedHigh confidence
Trains the data-security posture that keeps customer objects private.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection of a public-access change from posture monitoring and access logs.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains scoping which objects were exposed and actually read from access logs.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains making the bucket private and enabling account-wide public-access blocks.
- Secure Sensitive Data2.IMappedHigh confidence
Trains the sensitive-data baseline that keeps customer documents non-public.
- Asset Inventory1.AMappedMedium confidence
Trains knowing which buckets hold sensitive data so exposure is scoped fast.
- Data ProtectionControl 3MappedHigh confidence
Trains the data-protection control the exposure exercises.
- Audit Log ManagementControl 8MappedMedium confidence
Trains preserving the access logs that scope the read activity.