VPC peering misconfig exposes an internal database to a partner network
A hard Cloud Infrastructure scenario on VPC Peering Database Exposure.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.
catalog id · cloud-vpc-peering-database-exposure
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Close an unintended peering path to a production database
- Separate network reachability from proven database access
- Remote Services · Lateral MovementT1021 · TA0008PartialMedium confidence
Trains closing an unintended network path that could let a peered partner reach the production database.
- Network Traffic FilteringD3-NTFMappedHigh confidence
Trains tightening the security group and route so only the app tier reaches the database.
- Network Traffic AnalysisD3-NTAMappedHigh confidence
Trains using flow logs and DB auth logs to separate reachability from real access.
- Identity Management, Authentication, and Access Control · ProtectPR.AA · PRMappedHigh confidence
Trains the network access-control posture that keeps the DB off the partner path.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detecting partner-CIDR flows reaching the database subnet.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains distinguishing accepted flows from actual database logins.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains closing the DB path precisely without severing the legitimate peering.
- Network Segmentation2.FMappedHigh confidence
Trains the segmentation baseline that keeps a partner network off the data tier.
- Log Collection2.TMappedMedium confidence
Trains preserving flow and DB auth logs to scope the exposure.
- Network Infrastructure ManagementControl 12MappedHigh confidence
Trains the network-infrastructure control behind least-privilege routing and security groups.
- Network Monitoring and DefenseControl 13MappedHigh confidence
Trains the monitoring control that surfaced the partner-to-DB flows.