18 cards · Foundations, Practitioner, Applied, Advanced, Expert
Cloud interview questions and practice topics
Cloud security: IAM misconfiguration, metadata service abuse, storage exposure, Kubernetes and container security, and detection in AWS, Azure and GCP.
Each card is a topic to explain out loud against the clock: 10 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick Cloud as a focus.
L1 Foundations What it is
L2 Practitioner How it works
- AWS Keys Pushed to GitHubA key was leaked publicly and is already being used. What are your first 30 minutes?Incident · Interview
- Cloud Audit LoggingWhat cloud logs do you need on day one to investigate an incident later?Explain · Interview
- Envelope Encryption with KMSWhat is envelope encryption and why do cloud KMS services use it?Explain · Interview
- Root Account LoginIncident
L3 Applied Abuse and defence in real systems
- Capital One 2019 BreachDeep dive
- Crypto-Miner in the ClusterYou find a crypto-miner running in production Kubernetes. How do you work out how it got there?Incident · Interview
- Database Snapshot Made PublicIncident
- Instance Metadata and IMDSv2Why did SSRF vulnerabilities become so dangerous in AWS, and what does IMDSv2 change?Explain · Interview · Deep dive
- Least-Privilege IAMHow do you get an AWS account from wildcard policies to least privilege without breaking production?Explain · Interview
- Secrets in CI/CDHow should a CI pipeline authenticate to a cloud account to deploy?Explain · Interview · Deep dive
L4 Advanced Edge cases, bypasses, trade-offs
L5 Expert Research-grade, architecture-level
Other domains
Web AppSec · Network · Identity & AD · Cryptography · Blue team / DFIR · Malware & intel · Famous breaches · GRC · AI security