Lesson 5 of 6
Lesson 5 — Cloud Security and Shared Responsibility
The provider secures the cloud. You secure what you put in it — and most breaches happen on your side of that line.
Learn it
The provider protects the buildings, hardware and their own software. You protect your data, accounts and settings.
Most cloud breaches are misconfigurations: a storage bucket left public, or a password with no MFA.
Give every account the least access it needs, and encrypt data at rest and in transit.
Key terms
- Shared responsibility
- A split of security duties between provider and customer.
- IAM
- Identity and Access Management — who can do what to which resource.
- Least privilege
- Granting only the permissions strictly needed, for as short a time as possible.
- Misconfiguration
- An insecure setting, e.g. a public bucket — the top cause of cloud breaches.
- Audit log
- An immutable record of API actions used for detection and forensics.
Investigate a leaked bucket
A researcher emails: your school's exam scans are downloadable by anyone.
- 1Contain: Block public access at the account level, not just on that one bucket.
- 2Assess: Read the access logs: which objects were fetched, by which IPs, and when?
- 3Attribute: Check the audit trail for the IAM identity that changed the policy, and why.
- 4Prevent: Add a guardrail policy that denies public ACLs, plus an alert when one is attempted.
- 5Report: Personal data exposed means a data-protection notification duty with a legal deadline.
Least-privilege IAM policy
json{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": ["s3:GetObject"],
"Resource": "arn:aws:s3:::school-results-2026/reports/*",
"Condition": {
"Bool": { "aws:SecureTransport": "true" }
}
}]
}Read-only, one prefix of one bucket, HTTPS only. Compare with the tempting one-liner `"Action": "s3:*", "Resource": "*"` — which hands an attacker the whole account if the credential leaks.
Try it
Secure practice or security incident waiting to happen?
Access keys committed to a public GitHub repo 'just for testing'.
Admins log in with MFA and assume a role for 1 hour when they need power.
A bucket set to public-read so the mobile app 'can reach the files'.
Audit logs written to a separate, append-only account.
Challenge
A developer's laptop is stolen. It had long-lived cloud access keys with full admin rights. Write the incident response: immediate actions, investigation, and three changes so this can't hurt you again.
Pick whichever way suits you — every mode earns the same bonus XP.
Write at least 40 more characters to submit.
Mark your own work
Guided walkthrough — 0/3 clues revealed
- Clue 1 locked — reveal it only if you get stuck.
- Clue 2 locked — reveal it only if you get stuck.
- Clue 3 locked — reveal it only if you get stuck.
Each clue costs 5 XP (never below 24 XP). You'd earn 48 XP right now.