Define the cloud boundary
Identify the fictional service model, accounts, projects, regions, assets, owners, data, identities, dependencies, trust boundaries, and approved review scope.
Output: Cloud scope and responsibility map.
Learn how defenders protect fictional cloud identities, data, storage, networks, services, configurations, logs, recovery, and shared responsibilities. Build evidence-based cloud security decisions without accessing any real cloud account or private data.
Module
I13
Lessons
8
Assessment
25 questions
Portfolio
Cloud defense package
Main Question
Cloud security is not only about one provider dashboard or one exposed setting. A fictional environment may include customer identities, provider services, applications, storage, databases, networks, keys, logs, deployment systems, vendors, regions, and business owners. Each layer has a different responsibility and evidence boundary. This module teaches you to map those boundaries, identify meaningful risks, correlate several sources, and plan safe, owned, testable defensive action.
Safety and Authorization Boundary
Every account, project, identity, role, bucket, database, key, network, route, service, configuration, log, alert, incident, organization, owner, and decision in Module I13 is fictional. Do not sign in to, scan, test, query, change, export from, or investigate any real cloud environment. The labs focus on defensive reasoning from supplied training records.
Six-Step Cloud Defense Workflow
Identify the fictional service model, accounts, projects, regions, assets, owners, data, identities, dependencies, trust boundaries, and approved review scope.
Output: Cloud scope and responsibility map.
Record fictional users, service identities, roles, storage, databases, networks, public endpoints, keys, backups, logs, and critical services.
Output: Cloud asset and access inventory.
Evaluate fictional least privilege, encryption, private access, logging, segmentation, retention, recovery, configuration baselines, and owner requirements.
Output: Control comparison and evidence gaps.
Consider fictional exposure, privilege, data sensitivity, reachability, exploitability, business effect, evidence confidence, and compensating controls.
Output: Risk-ranked cloud findings.
Assign fictional owners, approvals, containment, remediation, validation, rollback, monitoring, communication, and completion evidence.
Output: Cloud defense action plan.
Confirm fictional control effectiveness, residual risk, source health, evidence lineage, reviewer approval, lessons learned, and portfolio-safe reporting.
Output: Validated closure and portfolio package.
Module Objectives
Objective 1
Explain fictional cloud service models, shared responsibility, trust boundaries, assets, owners, dependencies, and customer-versus-provider security duties.
Objective 2
Evaluate fictional cloud identities, roles, service accounts, temporary access, storage permissions, encryption concepts, networks, logging, and configuration baselines.
Objective 3
Use multi-source fictional evidence to distinguish direct observations, supported findings, alternatives, confidence, limitations, and missing evidence.
Objective 4
Prioritize fictional cloud risks using exposure, privilege, data sensitivity, reachability, business effect, source health, and compensating controls.
Objective 5
Design fictional cloud remediation and incident actions with owners, approvals, validation, rollback, monitoring, communication, and closure criteria.
Objective 6
Create a complete portfolio-safe cloud security package using only fictional systems, evidence, identities, data, routes, alerts, owners, and decisions.
Module Lessons
Understand fictional cloud service models, shared responsibility, trust boundaries, owners, assets, data flows, regions, accounts, subscriptions, projects, and the difference between provider controls and customer responsibilities.
Lesson focus
Safe fictional lab
Build a fictional shared-responsibility and cloud-asset map for the Northbridge Learning Cloud.
Analyze fictional users, service identities, roles, permissions, sessions, temporary access, federation, privileged paths, approvals, and access-review evidence without accessing any real cloud account.
Lesson focus
Safe fictional lab
Create a fictional cloud identity-and-access review with roles, risks, owners, evidence, and remediation decisions.
Study fictional object storage, databases, backups, encryption concepts, keys, versioning, retention, sharing, public access, classification, recovery, and data-lifecycle controls.
Lesson focus
Safe fictional lab
Review a fictional storage posture and design a safer data-protection plan.
Interpret fictional virtual networks, subnets, routes, gateways, security rules, private endpoints, load balancers, service exposure, segmentation, and network evidence.
Lesson focus
Safe fictional lab
Build a fictional cloud network exposure map and recommend defensive changes.
Use fictional control-plane, identity, storage, network, application, configuration, and billing records to identify meaningful signals, source-health limits, and detection gaps.
Lesson focus
Safe fictional lab
Create a fictional cloud monitoring coverage matrix and investigate a supplied alert.
Evaluate fictional cloud configuration drift, policy violations, exposed services, broad permissions, disabled logging, missing encryption, unmanaged resources, and change-control evidence.
Lesson focus
Safe fictional lab
Prioritize a fictional cloud posture backlog using evidence, exposure, impact, ownership, and safe validation.
Coordinate fictional cloud containment, identity protection, evidence preservation, configuration correction, recovery, validation, communication, and lessons learned across shared owners.
Lesson focus
Safe fictional lab
Build a fictional cloud incident action plan with owners, approvals, evidence, rollback, and closure criteria.
Integrate shared responsibility, identity, data protection, networking, logging, configuration defense, incident response, evidence reasoning, reporting, and portfolio-safe communication.
Lesson focus
Safe fictional lab
Complete the fictional Northbridge Learning Cloud integrated defense case.
Fake Evidence Preview
Identity signal
A fictional service role has broader storage permissions than its documented export workflow requires.
Configuration signal
A fictional storage container allows a wider network path than the approved private-service design.
Evidence boundary
Supplied audit records show no supported public sharing within verified coverage, but source and retention limits remain.
Module Portfolio Outcome
By the end of Module I13, you will create a fictional portfolio package containing a cloud responsibility map, asset inventory, identity review, storage and data-protection assessment, network exposure map, monitoring coverage matrix, misconfiguration backlog, incident action plan, evidence-based findings, technical report, leadership summary, validation plan, and portfolio-safety statement.
Module Assessment
After completing all eight lessons, take the exact-format 25-question module test. The assessment covers shared responsibility, identities, data protection, networking, logging, configuration defense, incident response, evidence limits, and portfolio-safe communication.
Module Navigation