W

Network Security Academy

Course: Vulnerability and Mitigation Class | Cloud Admin Sandbox

Mitigation Score: 0 / 100
Live Simulation Terminal v1.4.2-STABLE
[*] INITIALIZING SIMULATION ARCHITECTURE...
[*] FETCHING ENVIRONMENT STATUS...
[WARN] SOC ALERT: Anomalous outbound traffic detected originating from internal subnets.
[CRITICAL] External penetration vector detected matching pattern: CVE-2024-XXXX.
--- Awaiting System Diagnostics Assignment ---
admin@sec-ops:~$
Target Infrastructure Blueprint
Prod-Web-01 VULNERABLE
Type: Web Application Server
Flaw: Insecure Deserialization / Missing Update
Access: Publicly Exposed (Port 443/80)
Core-DB-Data EXPOSED
Type: Database Instance (Shared Subnet)
Flaw: Insecure Defaults / Cleartext Creds
Access: Accessible from Web Subnet
Internal-API UNHARDENED
Type: Application Endpoint
Flaw: Over-privileged service tokens
Access: Internal-only Routing
Mobile-Gateway RISK PROFILE
Type: Edge Gateway Asset
Flaw: Sideloading API trust configuration
Access: Consumer Mobile Sync
Active Engagement Matrix: Select Strategy to Match Vulnerability Profile

Review the system state. Attackers are attempting lateral movement from the web tier to the database tier using application misconfigurations and over-privileged connections. Select an asset, match the correct mitigation strategy framework, and hit deploy to execute.