3.4.3.3. Common Cloud Security Threats
3.4.3.3. Common Cloud Security Threats
Understanding common threats helps you design effective detection and prevention controls.
Top threats for the DOP-C02 exam:
| Threat | Detection Service | Prevention |
|---|---|---|
| Credential compromise | GuardDuty (UnauthorizedAccess:IAMUser) | MFA, role-based access, short-lived credentials |
| Data exfiltration | GuardDuty + Macie + VPC Flow Logs | VPC endpoints, S3 bucket policies, NACLs |
| Privilege escalation | CloudTrail + Access Analyzer | Permissions boundaries, SCPs |
| Crypto mining | GuardDuty (CryptoCurrency:EC2) | IMDSv2, security groups, monitoring |
| Supply chain attack | Inspector + ECR scanning | Image signing, CodeArtifact policies |
| DDoS | Shield + WAF | CloudFront, rate limiting, auto scaling |
| Misconfiguration | Config + Security Hub | SCPs, Service Catalog, cfn-guard |
Instance metadata service (IMDS) attacks: Attackers exploit SSRF vulnerabilities to steal instance credentials via the metadata endpoint (169.254.169.254).
IMDSv2 mitigation:
# Require IMDSv2 (token-based) — blocks SSRF attacks
aws ec2 modify-instance-metadata-options \
--instance-id i-1234567890abcdef0 \
--http-tokens required \
--http-put-response-hop-limit 1
IMDSv2 requires a PUT request to get a session token before accessing metadata — SSRF attacks can't perform the two-step process.
--http-put-response-hop-limit is the number of network hops the token (PUT) response may travel. At 1 the token can't leave the instance itself, so neither a container (an extra hop) nor another host using the instance as an open firewall, NAT or router can obtain one; AWS suggests 2 only where containers genuinely need IMDS. (Open reverse proxies are stopped differently: IMDSv2 refuses token requests that carry an X-Forwarded-For header.) Pair both with a least-privilege instance role, so any credentials that do leak have a small blast radius. Network ACLs and security groups are no help here: they don't filter traffic to the instance metadata service at all.
Exam Trap: GuardDuty finding UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS means instance role credentials are being used from outside AWS (not from the instance). This is a strong indicator of credential theft. The correct response is: rotate the role credentials (by revoking active sessions), investigate the instance for compromise, and enable IMDSv2 if not already required. Before any of that, isolate the instance by swapping in an isolation security group rather than terminating it, because the evidence is on it. Detaching and re-attaching the instance profile does not invalidate credentials the attacker already holds, and a network ACL can't stop API calls made from outside your VPC. Revoking the role's active sessions is what cuts the stolen credentials off.