Prepare evidence before the incident
The lab mounts a Metadata policy before creating the API server. It records requests in both exercise namespaces and changes to ClusterRoles and ClusterRoleBindings; other requests fall outside this selection. This supports studying a known sequence without collecting Secret contents. In a real service, identify required events, owners, destination, access and retention period before cutover. Do not present absence of an event outside the policy as evidence of no activity. The PM should request an operational search and interpretation rehearsal as well as confirming that a log file exists.
Link each result to the correct request
Each client request receives an Audit-Id. The script finds its ResponseComplete event and compares the HTTP code with the client observation. It also checks the authenticated ServiceAccount and absence of impersonation. The unique userAgent helps select the run; it must not be treated as authenticated identity. Request count can vary if attempts occur during change propagation, so verification compares identifiers and outcomes rather than fixed counts alone. Retain timestamps and scope when constructing the timeline. This local correlation does not validate a provider’s distributed clocks or pipelines.
Distinguish access, content and subsequent use
The synthetic Secret was returned to the client during the broad grant. The client checked the marker in memory; the report stores only that the comparison passed. Its 200 Metadata event identifies the request and result without storing the response body. The script checks that the marker, its base64 form and the token are absent from this exercise’s raw log. This does not establish that every organizational log is free of sensitive data. Nor does a read event prove the subsequent destination of its content. For the fictional incident, report observed access and outstanding investigation into use, copies and consequences.
Contain while preserving the required service
The containment sequence removes the broad grant, confirms new Secret and B reads are denied and preserves the status read in A. Removing the last RoleBinding also breaks that legitimate read; restoring the minimum binding recovers it without recovering Secret access. This controlled regression teaches testing continuity and isolation within the same change. In real operations, a credential read during exposure may need replacement coordinated with consumers; removing a binding does not withdraw an already obtained copy. Define the decision owner, dependencies, verification and escalation before executing an action that could affect daily closing.
Close the incident with explicit limits
The exercise dossier contains versions, script hash, checks, selected events and cluster-removal record. A hash helps compare bytes but alone neither authenticates the collector nor establishes custody. The log stayed on the temporary node; SIEM delivery, immutable storage and resistance to a hostile administrator were not demonstrated. To close a real incident, connect each assertion with suitable evidence, document gaps and confirm residual-action owners. Thirty local results do not establish containment across an entire cloud platform. Summary: collect before evidence is needed, correlate requests, distinguish observation from inference and verify legitimate access after containment.
The same token reads a Secret before binding removal and receives 403 afterwards while still authenticating.
Common pitfalls
Testing only allowed paths; overlooking additional bindings; confusing 403 with a revoked token; inferring content or exfiltration from Metadata.
Related topics: Identity, tokens and authorization · Change, evidence and incident response
Correlate evidence, constrain conclusions and recover operational access after containment.
Reference: Auditing · CCSP examination outline effective 2026-08-01; January2026 V2 PDF