Two simulated consoles at Northline Analytics. Name the customer-owned misconfiguration, the first fix, and the evidence that would show it is gone.
Step 1 of 3
Case A shows public GetObject on customer-exports/. Who owns that mistake?
CASE REFLECTION
Keep the reasoning.
first decisions matched the scenario’s best-supported answer.
On these screenshots the mistake is customer configuration and identity, not the provider’s buildings. Name the owner, make the smaller policy, and keep the diff that shows the public path and the wildcard are gone.
Responsibility table for Northline Analytics (simulated).
Case
Owner
First fix
Verification
A · public GetObject
Customer: configuration, identity, and data
Block public access and remove Principal * from customer-exports/
Policy diff plus public-access block on; simulated access-analyzer finding cleared
B · Action * / Resource *
Customer: the workload role
Replace the wildcard with the job’s read on one prefix
Policy diff; denied call outside that prefix; role still not a human MFA session