- From
- Cloud Posture Monitoring <cspm-alerts@acme-corp.io>
- To
- cloudsec@acme-corp.com
- Date
- 2026-05-04 08:42 UTC
Public object-storage bucket exposed — customer files world-readable
Attempt 1 of 1 · cmqixvoql00030kyz2a95212u
This is your first attempt for this scenario. Retry the scenario to generate a side-by-side comparison against your previous response.
Not enough data yet · Cloud Infrastructure
You have 1 of 3 attempts at Easy. Complete 2 more to unlock a recommendation. (Track: Cloud Infrastructure)
Sample size: 1
# Current bucket access (read-only view from CSPM)
Bucket: acme-customer-docs
Effective access: PUBLIC-READ (principal "*", action getObject/listObjects)
Default new-object ACL: inherits bucket policy (public)
Object count: ~4,300 documents
Encryption at rest: enabled (provider-managed key)
# Bucket policy change history (last 24h)
2026-05-03 18:55 UTC policy updated by user 'svc-onboarding-deploy'
statement added: Allow "*" getObject,listObjects
(previous policy: private, owner-account only)
# Access-log sample (last 14h, anonymized source IPs)
2026-05-03 19:02 GET listObjects 200 src=ASN-not-in-allowlist (cloud range)
2026-05-03 19:03 GET getObject /onboarding/id-scan-1182.pdf 200 4 requests
2026-05-04 02:10 GET listObjects 200 src=multiple external ranges
-- reads are from outside the corporate / known-partner ranges
# Controlled distractors (rule out wider faults)
Other 11 buckets in the account: all still private (CSPM scan clean)
No IAM user/role was deleted; no encryption key was disabled.- Name
- acme-customer-docs (object-storage bucket)
- Type
- Cloud object storage holding customer onboarding documents (PII); currently public-read; encrypted at rest; ~4,300 objects
- Owner
- Cloud Security · Data Platform
- Level
- High
I don't know how to respond to this
The response is missing several critical incident response steps. Review the rubric and try again. Score: 1/100. Strongest area: Clarity & structure (13%). Weakest area: Misconfiguration / threat understanding (0%) — expand this next time. The response is quite short; aim for a more structured, step-by-step plan.
Where points came from
- Misconfiguration / threat understanding0/3 · 0.0 / 15
- Cloud asset & blast-radius impact0/3 · 0.0 / 10
- Cloud risk prioritization0/2 · 0.0 / 10
- Cloud (revoke / restrict / isolate)0/3 · 0.0 / 20
- Cloud log & investigation0/4 · 0.0 / 15
- Recovery & hardening0/3 · 0.0 / 10
- Cloud evidence preservation ( / logs)0/3 · 0.0 / 10
- Clarity & structure0/2 · 1.3 / 10
Strengths
No category reached 70% coverage.
Missing / weak
- Misconfiguration / threat understanding
- Cloud asset & blast-radius impact
- Cloud risk prioritization
- Cloud (revoke / restrict / isolate)
- Cloud log & investigation
- Recovery & hardening
- Cloud evidence preservation ( / logs)
- Clarity & structure
Dangerous actions detected
None detected in your response.
Learn from this attempt
Post-submission coaching for this scenario. Score and verdict are unchanged — these notes are for your next attempt.
Why points were deducted
- Cloud containment (revoke / restrict / isolate)0% coverage
Make the bucket private and enable account-wide block-public-access; never delete the bucket/objects to silence the alert.
- Misconfiguration / threat understanding0% coverage
Name the misconfiguration: a bucket policy / object ACL granting anonymous public-read to PII, not a 'hack'. Explain why that is exposure.
- Cloud log & IAM investigation0% coverage
Use the policy-change history and storage access logs to scope who changed it and which objects were actually read.
Model answer outline
A service account ('svc-onboarding-deploy') changed the 'acme-customer-docs' bucket policy ~14h ago to allow anonymous public-read of ~4,300 customer onboarding documents (PII). Access logs show reads from outside the known ranges, so this is a real data-exposure incident, not a theoretical one.
Rated SEV-3 / P3. Treat as a high-priority data-exposure incident: PII is involved and the bucket was reachable by anyone.
- Treat as a high-priority data-exposure incident: PII is involved and the bucket was reachable by anyone.
- Engage Cloud Security and the Data Platform owner together; flag Privacy/Legal early in case notification is required.
- Close the exposure first, but preserve the evidence needed to scope what was read.
- Make the bucket private — remove the public-read statement / principal '*' and restrict to the owner account.
- Enable account-wide block-public-access so a single bad policy cannot re-open it.
- Do not delete the bucket or its objects to 'make it go away' — that destroys evidence and customer data.
- Read the bucket policy change history to confirm who/what made the change (svc-onboarding-deploy) and when.
- Pull the storage access logs to scope which objects were listed/downloaded and from which external ranges.
- Distinguish 'public ACL existed' from 'objects were actually read' — the logs show real external reads here.
- Rule out the distractors: other buckets are private, no IAM principal deleted, encryption key intact.
- Set account-level block-public-access and a default-private posture for new objects.
- Add a CSPM guardrail / policy-as-code rule that alerts on (or blocks) any public-read change.
- Scope the 'svc-onboarding-deploy' permissions down to least privilege so it cannot set public policies.
- Export and retain the access logs before any cleanup, with timestamps and source ranges.
- Capture the before/after bucket policy diff and the policy-history entry of the change.
- Open an incident ticket with the timeline so Privacy/Legal can assess notification obligations.
- Brief Cloud Security, the data owner, and Privacy/Legal once the exposure window and accessed-object list are bounded.
- Prepare facts (what, how long, what was read) rather than speculation for any breach-notification decision.
- Document the root cause (deploy role could set public policy) so the fix is auditable.
- Do not delete the bucket or its objects before evidence is preserved.
- Do not clear or disable the access logs.
- Do not leave the bucket public 'until business hours'.
- Do not assume nothing was read — the logs prove external access.
Dangerous actions to avoid
- Do not delete the bucket or its objects before evidence is preserved.
- Do not clear or disable the access logs.
- Do not leave the bucket public 'until business hours'.
- Do not assume nothing was read — the logs prove external access.
How to improve next time
- Close the public access first, but do it by making the bucket private — never by deleting data or logs.
- Separate 'was public' from 'was read': the access logs tell you the real .
- Account-wide block-public-access is the durable fix; a one-off policy edit can be undone by the next bad deploy.
- Loop in Privacy/Legal early when PII is involved so any notification decision is fact-based.
- Preserve the access logs and the policy diff before cleanup — they are your evidence.
Request an AI review of this attempt
This AI review is supplemental coaching. It does not change your official score or verdict. The review is only kept for this page session and is not saved permanently.
AI Tutor
This tutor explains your result. It does not change your score. Pick a question to see how the deterministic grading reached your verdict and where to focus next.
Generated deterministically from your graded result — no AI model was called.
Why did I get this score?
Your verdict was Fail at 1/100. That total is the sum of deterministic rubric points across 8 categories — each scores how much of its expected, ordered steps your answer covered, not an opinion about your writing. Your strongest coverage was Clarity & structure (13%). Points were held back mostly in Cloud containment (revoke / restrict / isolate) (0%), Misconfiguration / threat understanding (0%), Cloud log & IAM investigation (0%).
Re-read the cloud containment (revoke / restrict / isolate) expectations for this scenario and list the concrete steps you missed.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
What should I improve first?
Focus on Cloud containment (revoke / restrict / isolate) first — it is your weakest rubric area at 0% coverage and carries weight 20. For this scenario: Make the bucket private and enable account-wide block-public-access; never delete the bucket/objects to silence the alert.
Rewrite your cloud containment (revoke / restrict / isolate) section as a short numbered checklist before your next attempt.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
How does my answer compare to the model answer outline?
Compared with the model answer outline, the most useful sections to study are the ones matching your weak areas. Re-read the outline's cloud containment (revoke / restrict / isolate), misconfiguration / threat understanding, cloud log & iam investigation guidance and check which listed points you did not cover. The outline is a high-level checklist of expected points — use it to find gaps, not to copy a finished answer.
Pick one model-answer section you missed and add its key points to your next response in your own words.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
Which rubric area mattered most here?
Cloud containment (revoke / restrict / isolate) mattered most here: it carries the highest rubric weight (20), so coverage there moves your score the most. You covered 0% of it this time, worth 0 points.
Prioritise the highest-weight categories first; make sure cloud containment (revoke / restrict / isolate) is fully addressed before lower-weight ones.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
What should I study next?
Based on this attempt, study cloud containment (revoke / restrict / isolate), misconfiguration / threat understanding, cloud log & iam investigation next. Coaching tip for this scenario: Close the public access first, but do it by making the bucket private — never by deleting data or logs.
Close the public access first, but do it by making the bucket private — never by deleting data or logs.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
Coach Notes
Open full notebook →Save study notes for this attempt. They also collect in your mistake notebook.
Loading notes…