SecurityCipherInteractive labs All labs Cloud ยท AWS โœ•

Architecture Review: AWS 3‑Tier Web App

00:00 0/8 flagged
Intermediate Cloud ยท AWS ShopStream ยท B2C Web & REST API

Click any cloud component to inspect its configuration snapshot, network routes, and security groups. Flag specific settings that violate cloud security best practices.

Focus:
120%
๐Ÿข VPC ยท 10.0.0.0/16 ยท us-east-1
๐ŸŒ Public Subnet ยท 10.0.1.0/24 (DMZ)
โšก Private Subnet ยท App Tier ยท 10.0.2.0/24
๐Ÿ—„๏ธ Private Subnet ยท Data Tier ยท 10.0.3.0/24
๐Ÿ›ก๏ธ Shared & Managed Services
Public Internet

Your Findings

0 / 8
Crit: 0/3 High: 0/4 Med: 0/1

Flagged misconfigurations. Click any finding to inspect on diagram, or click ร— to unflag.

๐Ÿ”
No settings flagged yet
Click any service on the diagram to inspect its configuration and flag security flaws.

Review Objectives

  • 8 Total Flaws: 3 Critical, 4 High, 1 Medium.
  • Inspect on Diagram: Click any service box to view security groups, policies, and encryption.
  • Scoring Rules: +12.5 pts per real flaw. -8 pts penalty for false positives.

Stuck?

Reveal a category-level nudge without giving away the exact answer. Costs a few points.

Threat Model Scenario

ShopStream ยท AWS 3-Tier Web App

Target Application Architecture

ShopStream is a high-volume B2C storefront and customer API deployed in AWS (us-east-1). The infrastructure comprises an external Application Load Balancer terminating TLS, an Auto Scaling Group of stateless EC2 application servers running API endpoints, a PostgreSQL RDS database cluster, an S3 bucket for public media assets, and an ops bastion host.

Data Classification: High Sensitivity โ€” Customer PII, shipping addresses, hashed credentials, and tokenized payment records are stored in PostgreSQL. Launch configuration templates should never contain secrets.

Trust Boundaries & Network Segregation

  • Tier 1 โ€” DMZ (Public Subnet): Internet Gateway, Internet-facing ALB, NAT Gateway, and Break-glass Bastion. Only HTTPS (443) should be exposed to 0.0.0.0/0.
  • Tier 2 โ€” App Tier (Private Subnet): EC2 Auto Scaling instances. Must only accept traffic forwarded from the ALB security group on port 8080. Outbound internet egress routed via NAT Gateway.
  • Tier 3 โ€” Data Tier (Private Subnet): RDS PostgreSQL instance. Must NEVER possess a public IP and must only accept TCP:5432 from the App Tier security group.
  • Shared Services: S3 Bucket, IAM Role, and CloudWatch / CloudTrail / VPC Flow Logs.

Review Objectives & Rules of Engagement

1
Inspect Each Component: Click every service box across the 3 tiers and shared services to inspect its security groups, encryption, and policies.
2
Flag Specific Misconfigurations: Check the checkbox for unsafe settings (e.g. 0.0.0.0/0 ingress, disabled encryption, wildcard privileges). Flagging safe settings results in false positive penalties (-8 pts).
3
Identify All 8 Flaws: Exactly 8 real security misconfigurations exist across this architecture, spanning Critical, High, and Medium severities.
4
Standards Mapped: Every finding is evaluated against the CIS AWS Foundations Benchmark and MITRE ATT&CK for Cloud matrix.

Scored Evaluation

Score begins at 0 and maxes at 100 points. Points are awarded for each real flaw detected (+12.5 pts). Penalties apply for false positives (-8 pts) and hints used (-4 pts). Submit when confident!

0/ 100
โ€”

โ€”

0/8Found
0Missed
0False positives
0:00Time taken

Findings breakdown (8 issues)