
ILT-U-621
Cloud Application and Configuration Security Proficiency Test. Aligned with the App Defense Alliance Cloud Application and Configuration Assessment Framework
Determination | Method |
| D-01 Public Storage Exposure | Identify and validate unauthenticated access to cloud storage objects. |
| D-02 Metadata Disclosure | Analyze exposed objects and determine whether metadata reveals security-relevant information. |
| D-03 Broken Object Authorization | Test access controls by requesting resources belonging to other users. |
| D-04 Cross-Tenant Access | Assess tenant isolation by attempting access to resources belonging to different tenants. |
| D-05 Excessive IAM Permissions | Analyze application behavior and available information to determine whether permissions exceed operational requirements. |
| D-06 Permission Scope | Validate the effective scope of excessive permissions through controlled access testing across tenant boundaries. |
| D-07 Undocumented Endpoint Discovery | Perform application and API enumeration to identify undocumented functionality. |
| D-08 Sensitive Information Disclosure | Analyze undocumented interfaces to determine whether operational or security-sensitive information is exposed. |
| D-09 Logging Coverage | Evaluate whether security-relevant activities generate corresponding audit records. |
| D-10 Monitoring Effectiveness | Assess whether suspicious or unauthorized activities produce alerts or detection mechanisms. |
| D-11 Vulnerability Correlation | Analyze relationships between identified weaknesses and determine potential attack paths. |
| D-12 Full Exploitation Path | Demonstrate and document a complete attack chain leading to cross-tenant compromise. |
| D-13 Confidentiality Impact | Assess the impact of identified weaknesses on the confidentiality of tenant data. |
| D-14 Tenant Isolation Impact | Evaluate the impact of findings on logical separation between tenants. |
| D-15 Monitoring Impact | Assess the operational consequences of insufficient logging and monitoring controls. |
| D-16 Decoy Validation | Validate the exposed API key or other indicators and determine whether they represent genuine security findings. |

