AI-assistant-generated snippet committed a live cloud key; CI then ran unexplained jobs and cloud reads with an ambiguous trail
A extremely-hard Cybersecurity scenario on AI Code-Assistant Secret-Leak Cascade.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 6 templates in this Track + Difficulty pool.
catalog id · ai-code-assistant-secret-leak-cascade
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Leaked-credential rotation and blast-radius scoping
- Secure CI identity and AI-generated-code secret hygiene
- Credentials In Files · Credential AccessT1552.001 · TA0006MappedHigh confidence
Trains response to a live credential committed into code and a ticket.
- Cloud Accounts · Initial AccessT1078.004 · TA0001PartialMedium confidence
Trains reasoning about possible reuse of the leaked cloud credential.
- User Account ContainmentD3-UACMappedHigh confidence
Trains rotating/revoking the compromised CI credential first.
- User Account PermissionsD3-UAPMappedHigh confidence
Trains least-privilege rebuild of the CI deploy identity.
- Incident Mitigation · RespondRS.MI · RSMappedHigh confidence
Trains credential rotation and blast-radius containment.
- Incident Recovery Plan Execution · RecoverRC.RP · RCMappedMedium confidence
Trains sequenced recovery onto a new least-privilege identity.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains rotate-before-scrub sequencing under an ambiguous trail.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains bounding the cloud blast radius despite log gaps.
- Detecting Relevant Threats and TTPs3.AMappedMedium confidence
Trains detection and attribution of anomalous CI/cloud activity.
- Vendor/Supplier Cybersecurity Requirements2.RPartialLow confidence
Trains governance of AI-assistant tooling and contractor access.
- Application Software SecurityControl 16MappedHigh confidence
Trains secret-scanning and secure handling of AI-generated code.
- Access Control ManagementControl 6MappedHigh confidence
Trains short-lived, least-privilege CI identity over long-lived keys.