Open cardosec

Case BE3BED · Cloud · L3 Applied

Database Snapshot Made Public

Practise as: Incident drill

Live alertCSPM alert: an RDS snapshot of the customer database was shared publicly 6 hours ago by an engineer role during a migration.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Revoke public sharing now, then determine whether any external account copied or restored the snapshot
  2. CloudTrail shows who changed the attribute and when; copies by other accounts may not appear in your logs
  3. Assume exposure if you cannot prove no access: involve legal and privacy for breach-notification assessment
  4. Encrypted RDS snapshots cannot be shared publicly, so this one was unencrypted; CMK snapshots shared to accounts need key access
  5. Prevent with an SCP denying public snapshot sharing and mandatory CMK encryption for data stores

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.