Topic33 problems· 1 reviewed

Cloud Security and Governance

33 incident problems about Cloud Security and Governance. Start with the reviewed ones.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

All problems (33)

S3 AccessDenied: the IAM policy allows it but the bucket policy denies itS3 AccessDenied: the IAM policy allows it but the bucket policy denies it is a hands-on troubleshooting drill. Read the explicit-deny wording in AccessDenied and fix access through the approved path. AWS cloud-security-and-governance needs to be checked by narrowing scope, rec...ReviewedSecurityIntermediate17 minFreeSECURITY-152A browser isolation policy renders the admin portal remotely, but a direct-download allowlist still lets CSV exports bypass the isolated sessionThe riskiest interaction is protected, yet a side path still leaks the sensitive payload.SecurityIntermediate16 minFreeSECURITY-157A web proxy enforces SafeSearch through DNS rewriting, but one application hardcodes HTTPS endpoints and bypasses the control entirelyName-based filtering works where DNS is consulted, but one client path never asks DNS again.SecurityIntermediate15 minFreeSECURITY-149A CloudFront signed URL policy covers the main asset host, but a redirect to the image host drops the signature scope and private media leaks a 403 loopThe control is present, yet the delivery path crosses hostnames that do not share the same authorization contract.SecurityAdvanced17 minProSECURITY-381A snapshot policy copies encrypted data correctlyA snapshot policy copies encrypted data correctly focuses on cloud-security-and-governance and asks the reader to isolate Permission Denied in AWS. 실무에서는 permission-denied 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다.SecurityAdvanced17 minProSECURITY-135An AWS IAM permissions boundary copied from a template blocks kms:Decrypt in the break-glass role and recovery automation fails during an incidentThe emergency role exists, yet one inherited boundary quietly removes the exact permission the runbook requires.SecurityAdvanced17 minProSECURITY-318A backup or snapshot path is readable while cross-account or cross-region recovery still lacks the exact decrypt or restore permission it needs during a failover rehearsalThe artifact exists and the recovery scope where it matters is still unauthorized. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-234A backup snapshot restores while the copy role still lacks the right to re-encrypt in the target account during a failover rehearsalDisaster recovery looks viable until the protected copy has to become live elsewhere. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-180A cloud permission exists in one region while the recovery workflow executes in another scope during a failover rehearsalThe right grant is present and absent at the same time depending on where the workflow actually runs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-124A presigned URL is valid, but the CDN cache key ignores one scoping parameter and content becomes reusable outside the intended request contextObject access control is strong at origin, yet the edge cache weakens it by collapsing distinct authorization contexts.SecurityAdvanced18 minProSECURITY-160A ransomware isolation workflow snapshots the volumes correctly, but the snapshot retention tag is missing and cleanup automation deletes the evidence before triage startsContainment worked, yet incident preservation failed because the evidence path lacked lifecycle protection.SecurityAdvanced18 minProSECURITY-104A rotated KMS key policy omits the legacy alias and historical backup decrypt operations fail during recoveryNew encrypt operations work, but restore testing fails because the recovery path still references an alias that the new policy no longer permits.SecurityAdvanced18 minProSECURITY-210An authorization token is valid for one delivery host while the content path crosses into another during a failover rehearsalAuthorization is scoped correctly and the asset path does not stay where the token applies. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-111CloudTrail shows the access denies, but the missing service-linked role auto-creation was never logged in the regional trail you checkedThe permissions symptom is real, yet the causal event lives in a different audit scope than the one the team has been searching.SecurityAdvanced18 minProSECURITY-134A CASB inline proxy rewrites the downloaded filename, and the DLP hash allowlist no longer matches the approved documentContent is safe, yet the downstream control no longer recognizes it because one enforcement layer changed the file artifact identity.SecurityAdvanced16 minProSECURITY-114A bucket policy blocks public reads, but the legacy website endpoint still exposes content through an old object ACLThe new policy appears strict, yet one access path bypasses it because object-level permissions were left behind from the static site era.SecurityAdvanced17 minProSECURITY-158A cross-account access analyzer stays green, but a new resource policy grants a service principal wildcard that the analyzer scope does not flag in this org layoutVisibility tooling is present, yet its scope is narrower than the real exposure surface.SecurityAdvanced17 minProSECURITY-155A DLP sensor classifies the document correctly, but a newly compressed archive format bypasses the extraction depth limit and the policy never sees the payloadContent controls are configured, yet packaging format changed the scanner's visibility boundary.SecurityAdvanced17 minProSECURITY-144A new KMS grant allows the backup role to decrypt snapshots, but the grant was created in one region and cross-region restore still failsThe permission exists, just not in the control-plane scope the recovery workflow actually uses.SecurityAdvanced17 minProSECURITY-128S3 encryption enforcement is enabled, but a legacy multipart client omits the required KMS context and uploads start failing midstreamThe bucket policy is correct, yet one older client implementation cannot satisfy the newer encryption contract.SecurityAdvanced17 minPro