Extra Challenges
Finished early? These deepen the investigation muscle.
E1 Suspicious activity
- Investigation → Activities, filter AWS.
- Find the failed logins and failing queries.
- Find an AssumeRole event; use the Session link to see the real actor.
E2 Effective permissions for a user
- Pick any AWS user; Access Review → New Report, Type=File, Tags=sensitive.
- Open Access Graph, Permission Source, Permission Summary.
Staleness needs time
Stale users / keys / policies require 90–180 days, so they won't appear in a fresh account. On real environments these are often the biggest wins.

