← All hands-on labs
AWS Security LabsBeginner~30 minBrowser · no setupFree · 2 launches · 24h window

S3 misconfiguration & data exposure

Find and fix public buckets, weak ACLs, and missing encryption in a realistic account.

S3IAMEncryptionCloudTrail

What you'll do

  • Work in a real, isolated AWS environment — nothing to install or set up
  • Find and exploit the weakness the way an attacker would
  • Apply the fix and verify it like a defender
  • Map what you did back to real-world controls and frameworks

Skills you'll gain

  • S3 Block Public Access & bucket policies
  • Default encryption (SSE) enforcement
  • TLS-only bucket policies
  • Least-privilege IAM remediation

Roles this maps to

Cloud Security EngineerCloud Security AnalystDevSecOps Engineer

Practical, job-aligned skills you can put on a résumé and demonstrate in interviews — proven against real cloud state, not multiple-choice.

You won't get stuck

Hit Check my work — graded against the live AWS account.

No static checklist. Our auto-grader assumes a role in your lab account and verifies real cloud state — if you only half-fixed it, you'll know. Per-objective ✅ / ⬜, instant.

Ready to launch this lab?

Spin it up in your browser — no setup. Your first lab is free.

24 people viewing now