incident-response-trainer
Incident response training · Rule-based scoring
DemoCatalogHistoryDashboard
← Back to catalog
Cloud InfrastructurehardVPC Peering Database ExposureCritical asset
Scenario

VPC peering misconfig exposes an internal database to a partner network

A hard Cloud Infrastructure scenario on VPC Peering Database Exposure.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.

catalog id · cloud-vpc-peering-database-exposure

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Close an unintended peering path to a production database
  • Separate network reachability from proven database access
MITRE ATT&CKmitre-attack
  • Remote Services · Lateral MovementT1021 · TA0008
    PartialMedium confidence

    Trains closing an unintended network path that could let a peered partner reach the production database.

MITRE D3FENDmitre-d3fend
  • Network Traffic FilteringD3-NTF
    MappedHigh confidence

    Trains tightening the security group and route so only the app tier reaches the database.

  • Network Traffic AnalysisD3-NTA
    MappedHigh confidence

    Trains using flow logs and DB auth logs to separate reachability from real access.

NIST CSF 2.0nist-csf-2
  • Identity Management, Authentication, and Access Control · ProtectPR.AA · PR
    MappedHigh confidence

    Trains the network access-control posture that keeps the DB off the partner path.

  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains detecting partner-CIDR flows reaching the database subnet.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains distinguishing accepted flows from actual database logins.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains closing the DB path precisely without severing the legitimate peering.

CISA Cybersecurity Performance Goalscisa-cpg
  • Network Segmentation2.F
    MappedHigh confidence

    Trains the segmentation baseline that keeps a partner network off the data tier.

  • Log Collection2.T
    MappedMedium confidence

    Trains preserving flow and DB auth logs to scope the exposure.

CIS Controls v8cis-controls
  • Network Infrastructure ManagementControl 12
    MappedHigh confidence

    Trains the network-infrastructure control behind least-privilege routing and security groups.

  • Network Monitoring and DefenseControl 13
    MappedHigh confidence

    Trains the monitoring control that surfaced the partner-to-DB flows.