EC-Council Certified Ethical Hacker (CEH) v12Cloud ComputingMedium

A security team is analyzing a recent data breach where an attacker exploited a misconfigured Identity and Access Management (IAM) policy in a cloud environment. The attacker gained unauthorized access to sensitive S3 buckets by leveraging overly permissive roles assigned to a compute instance. Which cloud computing threat category does this scenario primarily fall under?

  1. AAccount Hijacking
  2. BInsufficient Identity, Credential, and Access Management
  3. CInsecure Interfaces and APIs
  4. DShared Technology Vulnerabilities
Show answer & explanation

Correct answer: B. Insufficient Identity, Credential, and Access Management

The scenario explicitly describes an exploitation due to a misconfigured IAM policy and overly permissive roles, which directly relates to insufficient controls around identity, credentials, and access management within the cloud environment.

Why the other options are wrong

  • A. Account hijacking involves an attacker taking over legitimate user accounts, which is a possible outcome but not the root cause described.
  • C. While APIs are involved in IAM, the root cause was the policy misconfiguration, not an inherent insecurity in the API itself.
  • D. Shared technology vulnerabilities relate to flaws in hypervisors or underlying infrastructure, which is not indicated here.

Insufficient Identity, Credential, and Access Management (ICAM)

A cloud security threat arising from weak or poorly configured controls for managing user identities, authentication credentials, and access permissions.

  • Leads to unauthorized access.
  • Often results from overly permissive roles or misconfigured policies.
  • A common vector for data breaches in cloud environments.

Memory trick: IAM is like the bouncer; if they're weak, anyone gets in.

More Cloud Computing questions