Case E11F99 · Blue team / DFIR · L3 Applied
Incident Response in the Cloud
Practise as: Deep dive · Explain it
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Identity is the perimeter: investigate CloudTrail / Entra sign-in logs for API calls, not just host artifacts.
- Common signals: new access keys (CreateAccessKey), disabled logging (StopLogging), unusual regions.
- Contain by revoking sessions and keys, attaching deny policies, and isolating instances with restrictive SGs.
- Preserve evidence: EBS snapshots, memory captures before termination, and export logs past default retention.
- Shared responsibility: investigating your tenant is mostly on you; provider IR help is limited. Pre-stage IR roles and access.
If the interviewer pushes back
- An attacker used a leaked access key to call AssumeRole into production. How do you scope what they touched?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.