← All hands-on labs
AWS Security LabsBeginner~30 minBrowser · no setupFree · 2 launches · 24h window
S3 misconfiguration & data exposure
Find and fix public buckets, weak ACLs, and missing encryption in a realistic account.
S3IAMEncryptionCloudTrail
What you'll do
- Work in a real, isolated AWS environment — nothing to install or set up
- Find and exploit the weakness the way an attacker would
- Apply the fix and verify it like a defender
- Map what you did back to real-world controls and frameworks
Skills you'll gain
- S3 Block Public Access & bucket policies
- Default encryption (SSE) enforcement
- TLS-only bucket policies
- Least-privilege IAM remediation
Roles this maps to
Cloud Security EngineerCloud Security AnalystDevSecOps Engineer
Practical, job-aligned skills you can put on a résumé and demonstrate in interviews — proven against real cloud state, not multiple-choice.
You won't get stuck
Hit Check my work — graded against the live AWS account.
No static checklist. Our auto-grader assumes a role in your lab account and verifies real cloud state — if you only half-fixed it, you'll know. Per-objective ✅ / ⬜, instant.
Ready to launch this lab?
Spin it up in your browser — no setup. Your first lab is free.