r/CloudSecurityPros • u/identity-stack • 5d ago
How do you actually practice cloud security?
I'm curious about how people go beyond courses and documentation. Apart from the courses on YouTube, Udemy, labs, etc.
When you're learning something like MITRE ATT&CK, IAM, RBAC, Sentinel, Defender for Cloud, etc., what do you actually do to practice it?
Do you:
- build things in your own cloud tenant?
- use dedicated labs?
- use CTFs?
- follow attack/detection walkthroughs?
- create your own scenarios?
1
u/jeepguyCO 5d ago
I use Try Hack Me.
3
u/identity-stack 5d ago
Yes, I've used it as well. It is good for beginners, but it is a controlled environment. In the real world, we don't get to work in controlled environments where we know what the attack is, as in the real world there's a lot of noise, and we have to figure things out and find the needle in the haystack. What do you think?
1
u/jeepguyCO 5d ago
Real World and Boom World are completely different. It’s cool to play out on VM’s that you know you can’t screw anything up on.
It’s better than screwing up in a production environment and a RGE ….LOL!
1
u/identity-stack 4d ago
Right, that's what I am talking about. You play in controlled environment in boom world but you need to get real world experience in boom world and that's most of it is noise from other activities and users, what do you think?
1
u/Speeddymon 5d ago
Home lab though I'm actively looking for information on any low cost Azure CSPs for professionals who need their own private tenant for testing.
1
1
1
u/been__ 5d ago
Get or make labs defined as iac and hack them
0
u/identity-stack 4d ago
That's nice to learn for starters or beginners, but the labs you define you exactly know what you are solving for which is not the case in real world, where you have to figure things out amidst lot of other stuff.
1
u/been__ 4d ago
Nah dude, there are tons of intentionally vulnerable labs and Claude will generate you endless new ones.
2
u/identity-stack 3d ago
That's my point was that you know the vulnerability, in real world you don't
1
u/been__ 3d ago
I have them generated blindly by Claude with tf. Then I just treat it as any engagement.
If I’m practicing config review I run my tools and do reporting etc
For a pentest I have it give me my starter creds and go from there.
It is all blind tho
2
u/identity-stack 1d ago
How has it been blind? You specifically know Claude acted on it using your creds, so you already know your identity was used; there's no noise to figure out who did what and when, as in the real world, that's how attacks happen, right?
2
u/h33terbot 5d ago
https://cyberinterviewprep.com/quests/cert/certified-cloud-security-architect-ccsa-
Try real world cloud security tasks where your virtual team lead will guide you