High School IntermediateModule I138 Lessons + Module Test

I13 Cloud Security Basics

Learn how defenders protect fictional cloud identities, data, storage, networks, services, configurations, logs, recovery, and shared responsibilities. Build evidence-based cloud security decisions without accessing any real cloud account or private data.

Module

I13

Lessons

8

Assessment

25 questions

Portfolio

Cloud defense package

Main Question

How Can a Defender Reduce Cloud Risk without Losing Evidence, Privacy, Availability, or Ownership Clarity?

Cloud security is not only about one provider dashboard or one exposed setting. A fictional environment may include customer identities, provider services, applications, storage, databases, networks, keys, logs, deployment systems, vendors, regions, and business owners. Each layer has a different responsibility and evidence boundary. This module teaches you to map those boundaries, identify meaningful risks, correlate several sources, and plan safe, owned, testable defensive action.

Safety and Authorization Boundary

Use Only Fictional Cloud Evidence

Every account, project, identity, role, bucket, database, key, network, route, service, configuration, log, alert, incident, organization, owner, and decision in Module I13 is fictional. Do not sign in to, scan, test, query, change, export from, or investigate any real cloud environment. The labs focus on defensive reasoning from supplied training records.

Six-Step Cloud Defense Workflow

Scope, Inventory, Compare, Prioritize, Act, and Validate

1

Define the cloud boundary

Identify the fictional service model, accounts, projects, regions, assets, owners, data, identities, dependencies, trust boundaries, and approved review scope.

Output: Cloud scope and responsibility map.

2

Inventory identities, data, and exposure

Record fictional users, service identities, roles, storage, databases, networks, public endpoints, keys, backups, logs, and critical services.

Output: Cloud asset and access inventory.

3

Compare with secure expectations

Evaluate fictional least privilege, encryption, private access, logging, segmentation, retention, recovery, configuration baselines, and owner requirements.

Output: Control comparison and evidence gaps.

4

Prioritize cloud risks

Consider fictional exposure, privilege, data sensitivity, reachability, exploitability, business effect, evidence confidence, and compensating controls.

Output: Risk-ranked cloud findings.

5

Plan defensive action

Assign fictional owners, approvals, containment, remediation, validation, rollback, monitoring, communication, and completion evidence.

Output: Cloud defense action plan.

6

Validate and communicate

Confirm fictional control effectiveness, residual risk, source health, evidence lineage, reviewer approval, lessons learned, and portfolio-safe reporting.

Output: Validated closure and portfolio package.

Module Objectives

What You Will Be Able to Do

Objective 1

Explain fictional cloud service models, shared responsibility, trust boundaries, assets, owners, dependencies, and customer-versus-provider security duties.

Objective 2

Evaluate fictional cloud identities, roles, service accounts, temporary access, storage permissions, encryption concepts, networks, logging, and configuration baselines.

Objective 3

Use multi-source fictional evidence to distinguish direct observations, supported findings, alternatives, confidence, limitations, and missing evidence.

Objective 4

Prioritize fictional cloud risks using exposure, privilege, data sensitivity, reachability, business effect, source health, and compensating controls.

Objective 5

Design fictional cloud remediation and incident actions with owners, approvals, validation, rollback, monitoring, communication, and closure criteria.

Objective 6

Create a complete portfolio-safe cloud security package using only fictional systems, evidence, identities, data, routes, alerts, owners, and decisions.

Module Lessons

Eight Cloud Security Lessons

I13.1

Shared Responsibility and Cloud Security Foundations

Understand fictional cloud service models, shared responsibility, trust boundaries, owners, assets, data flows, regions, accounts, subscriptions, projects, and the difference between provider controls and customer responsibilities.

Lesson focus

  • Cloud service and deployment models
  • Provider, customer, and shared responsibilities
  • Assets, owners, trust boundaries, and data flows
  • Authorization, privacy, scope, and safe evidence use

Safe fictional lab

Build a fictional shared-responsibility and cloud-asset map for the Northbridge Learning Cloud.

I13.2

Cloud Identities, Roles, and Least Privilege

Analyze fictional users, service identities, roles, permissions, sessions, temporary access, federation, privileged paths, approvals, and access-review evidence without accessing any real cloud account.

Lesson focus

  • Users, groups, roles, and service identities
  • Least privilege and separation of duties
  • Temporary access and privileged workflows
  • Access reviews, ownership, and evidence limits

Safe fictional lab

Create a fictional cloud identity-and-access review with roles, risks, owners, evidence, and remediation decisions.

I13.3

Secure Cloud Storage and Data Protection

Study fictional object storage, databases, backups, encryption concepts, keys, versioning, retention, sharing, public access, classification, recovery, and data-lifecycle controls.

Lesson focus

  • Storage permissions and public-access prevention
  • Encryption and key-management concepts
  • Versioning, backup, retention, and recovery
  • Classification, minimization, and lifecycle decisions

Safe fictional lab

Review a fictional storage posture and design a safer data-protection plan.

I13.4

Cloud Networking and Service Exposure

Interpret fictional virtual networks, subnets, routes, gateways, security rules, private endpoints, load balancers, service exposure, segmentation, and network evidence.

Lesson focus

  • Virtual networks, subnets, routes, and gateways
  • Inbound and outbound access boundaries
  • Private services and public exposure
  • Segmentation, dependency mapping, and validation

Safe fictional lab

Build a fictional cloud network exposure map and recommend defensive changes.

I13.5

Cloud Logging, Monitoring, and Detection

Use fictional control-plane, identity, storage, network, application, configuration, and billing records to identify meaningful signals, source-health limits, and detection gaps.

Lesson focus

  • Cloud audit, identity, storage, and network logs
  • Monitoring coverage and source health
  • Detection logic and false-positive control
  • Timeline correlation and evidence lineage

Safe fictional lab

Create a fictional cloud monitoring coverage matrix and investigate a supplied alert.

I13.6

Cloud Configuration and Misconfiguration Defense

Evaluate fictional cloud configuration drift, policy violations, exposed services, broad permissions, disabled logging, missing encryption, unmanaged resources, and change-control evidence.

Lesson focus

  • Secure baselines and configuration drift
  • Misconfiguration evidence and prioritization
  • Policy, ownership, exception, and remediation
  • Validation, rollback, monitoring, and closure

Safe fictional lab

Prioritize a fictional cloud posture backlog using evidence, exposure, impact, ownership, and safe validation.

I13.7

Cloud Incident Response and Recovery

Coordinate fictional cloud containment, identity protection, evidence preservation, configuration correction, recovery, validation, communication, and lessons learned across shared owners.

Lesson focus

  • Cloud-specific incident roles and escalation
  • Identity, storage, network, and service containment
  • Evidence preservation and provider coordination
  • Recovery, validation, communication, and review

Safe fictional lab

Build a fictional cloud incident action plan with owners, approvals, evidence, rollback, and closure criteria.

I13.8

Cloud Security Basics Lab

Integrate shared responsibility, identity, data protection, networking, logging, configuration defense, incident response, evidence reasoning, reporting, and portfolio-safe communication.

Lesson focus

  • End-to-end fictional cloud security review
  • Evidence-based risk and control decisions
  • Owner, timeline, validation, and communication
  • Final cloud security portfolio artifact

Safe fictional lab

Complete the fictional Northbridge Learning Cloud integrated defense case.

Fake Evidence Preview

Northbridge Learning Cloud Security Review

Identity signal

A fictional service role has broader storage permissions than its documented export workflow requires.

Configuration signal

A fictional storage container allows a wider network path than the approved private-service design.

Evidence boundary

Supplied audit records show no supported public sharing within verified coverage, but source and retention limits remain.

Module Portfolio Outcome

Cloud Security Defense Package

By the end of Module I13, you will create a fictional portfolio package containing a cloud responsibility map, asset inventory, identity review, storage and data-protection assessment, network exposure map, monitoring coverage matrix, misconfiguration backlog, incident action plan, evidence-based findings, technical report, leadership summary, validation plan, and portfolio-safety statement.

Module Assessment

I13 Cloud Security Basics Module Test

After completing all eight lessons, take the exact-format 25-question module test. The assessment covers shared responsibility, identities, data protection, networking, logging, configuration defense, incident response, evidence limits, and portfolio-safe communication.

Module Navigation

Start Module I13