Cloud root/owner account MFA disabled — suspicious login from an unfamiliar IP
A easy Cloud Infrastructure scenario on Cloud Root/Owner Account MFA Disabled.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 3 templates in this Track + Difficulty pool.
catalog id · cloud-root-account-mfa-disabled
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Secure a cloud root/owner account with MFA after a suspicious login
- Review root activity and preserve sign-in evidence
- Valid Accounts: Cloud Accounts · Initial AccessT1078.004 · TA0001MappedHigh confidence
Trains response to a suspicious interactive login on a root/owner cloud account whose MFA is disabled.
- Multi-factor AuthenticationD3-MFAMappedHigh confidence
Trains re-enabling and enforcing MFA on the most-privileged account as the core fix.
- User Account ContainmentD3-UACMappedMedium confidence
Trains rotating root credentials and invalidating sessions when the login cannot be confirmed.
- Identity Management, Authentication, and Access Control · ProtectPR.AA · PRMappedHigh confidence
Trains the access-control posture that keeps the root/owner identity MFA-protected.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection of an anomalous root login and of MFA being disabled.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains re-enabling MFA and rotating root credentials as the containment action.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains confirming whether the root login was legitimate and reviewing what it did.
- Phishing-Resistant MFA2.EMappedHigh confidence
Trains the MFA baseline the disabled root account violated.
- Detection of Unsuccessful (Automated) Login Attempts2.QMappedMedium confidence
Trains the login-monitoring baseline that surfaces anomalous root access.
- Account ManagementControl 5MappedHigh confidence
Trains the account-management control for securing a privileged root account.
- Access Control ManagementControl 6MappedMedium confidence
Trains enforcing MFA and least privilege so root stays break-glass only.