Cloud Computing

Lesson 5 of 6

Lesson 5 — Cloud Security and Shared Responsibility

The provider secures the cloud. You secure what you put in it — and most breaches happen on your side of that line.

🔴 Advanced 95 XP

Learn it

The provider protects the buildings, hardware and their own software. You protect your data, accounts and settings.

Most cloud breaches are misconfigurations: a storage bucket left public, or a password with no MFA.

Give every account the least access it needs, and encrypt data at rest and in transit.

Key terms

Shared responsibility
A split of security duties between provider and customer.
IAM
Identity and Access Management — who can do what to which resource.
Least privilege
Granting only the permissions strictly needed, for as short a time as possible.
Misconfiguration
An insecure setting, e.g. a public bucket — the top cause of cloud breaches.
Audit log
An immutable record of API actions used for detection and forensics.

Investigate a leaked bucket

A researcher emails: your school's exam scans are downloadable by anyone.

  1. 1Contain: Block public access at the account level, not just on that one bucket.
  2. 2Assess: Read the access logs: which objects were fetched, by which IPs, and when?
  3. 3Attribute: Check the audit trail for the IAM identity that changed the policy, and why.
  4. 4Prevent: Add a guardrail policy that denies public ACLs, plus an alert when one is attempted.
  5. 5Report: Personal data exposed means a data-protection notification duty with a legal deadline.

Least-privilege IAM policy

json{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": ["s3:GetObject"],
    "Resource": "arn:aws:s3:::school-results-2026/reports/*",
    "Condition": {
      "Bool": { "aws:SecureTransport": "true" }
    }
  }]
}

Read-only, one prefix of one bucket, HTTPS only. Compare with the tempting one-liner `"Action": "s3:*", "Resource": "*"` — which hands an attacker the whole account if the credential leaks.

Try it

Secure practice or security incident waiting to happen?

Access keys committed to a public GitHub repo 'just for testing'.

Admins log in with MFA and assume a role for 1 hour when they need power.

A bucket set to public-read so the mobile app 'can reach the files'.

Audit logs written to a separate, append-only account.

Challenge

A developer's laptop is stolen. It had long-lived cloud access keys with full admin rights. Write the incident response: immediate actions, investigation, and three changes so this can't hurt you again.

Pick whichever way suits you — every mode earns the same bonus XP.

Write at least 40 more characters to submit.

Mark your own work

Guided walkthrough — 0/3 clues revealed

  1. Clue 1 locked — reveal it only if you get stuck.
  2. Clue 2 locked — reveal it only if you get stuck.
  3. Clue 3 locked — reveal it only if you get stuck.

Each clue costs 5 XP (never below 24 XP). You'd earn 48 XP right now.

Quiz time

Question 1 of 4Score 0

The leading cause of cloud data breaches is…