⛏️ Get Splunky!
Lv.1Intern
0 XP
0
Home Map Stats Drill Board Log In
Back to Floor
Scale Lab • Room 3

Cloud Security Architecture

Cloud environments introduce new data sources and attack surfaces. The architect ensures AWS CloudTrail, Azure Activity Logs, GCP Audit Logs, and cloud-native security tool outputs (GuardDuty, Defender for Cloud, Security Command Center) all flow into Splunk via the appropriate Add-ons.

The Shared Responsibility Model is central to cloud security architecture. The cloud provider secures the infrastructure (hypervisor, network, physical); the organization secures what runs on top (OS, applications, IAM configurations, data). Misconfigurations (overly permissive S3 buckets, open security groups) are the leading cause of cloud breaches and must be monitored continuously.

Cloud IAM is the new perimeter. An overly permissive IAM role is more dangerous than an open firewall port — it gives attackers the same capabilities as legitimate administrators.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
❤️❤️❤️
Question 1 of 1
According to the cloud Shared Responsibility Model, who is responsible for securing IAM user configurations in AWS?
AAWS — they manage all security
BThe customer — IAM configuration is above the cloud provider's responsibility boundary
CA third-party auditor
DNo one — IAM is secure by default