Interactive Lab
Find and Fix Risks in a College Event Registration App
A simulated scenario. No real AWS account required — practice the mindset first.
Trust score
0 / 100
Working but risky
Architecture: Student → Frontend → API → Backend Function → Database
Lab 1 — Hardcoded secret in code
Bad example
const API_KEY = "college-event-secret";
fetch(url, { headers: { Authorization: API_KEY } });What is the main risk here?
Lab 2 — IAM policy too broad
Bad example
{
"Effect": "Allow",
"Action": "*",
"Resource": "*"
}Which principle is violated?
Lab 3 — Missing structured logs
Bad example
print("success")Why is this bad for a production system?
Lab 4 — No audit trail
Bad example
// Admin updates Lambda config directly in console.
// No record of who changed what.What answers 'who changed what, when' in AWS?
Lab 5 — No compliance checks
Bad example
// S3 bucket public
// No encryption check
// No log retention ruleWhich AWS service continuously checks for these issues?