Case BE3BED · Cloud · L3 Applied
Database Snapshot Made Public
Practise as: Incident drill
Live alertCSPM alert: an RDS snapshot of the customer database was shared publicly 6 hours ago by an engineer role during a migration.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Revoke public sharing now, then determine whether any external account copied or restored the snapshot
- CloudTrail shows who changed the attribute and when; copies by other accounts may not appear in your logs
- Assume exposure if you cannot prove no access: involve legal and privacy for breach-notification assessment
- Encrypted RDS snapshots cannot be shared publicly, so this one was unencrypted; CMK snapshots shared to accounts need key access
- Prevent with an SCP denying public snapshot sharing and mandatory CMK encryption for data stores
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.