⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Staff SRE / Principal Architect [L3] Security Staff SRE Scenario [L3]

Q: A cloud-native application hosted on AWS EC2 allows users to input a URL, and the server fetches the image at that URL to generate a thumbnail. An attacker inputs `http://169.254.169.254/latest/meta-data/iam/security-credentials/`. What is this attack called, and how do you mitigate it at the infrastructure level?

This is a Server-Side Request Forgery (SSRF) attack. The attacker is tricking the server into making an HTTP request on their behalf to t...

#Security #Security #L3 #DevSecOps #Compliance #IAM
🎙️ Candidate Opening & Architectural Context
""In our DevSecOps implementation, we solved this by introducing automated security quality gates. The interviewer is testing: Server-Side Request Forgery (SSRF), IMDSv1 vs IMDSv2, cloud metadata risks.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Production Solution & Architecture

This is a Server-Side Request Forgery (SSRF) attack. The attacker is tricking the server into making an HTTP request on their behalf to the internal AWS Instance Metadata Service (IMDS). Because the request originates from the EC2 instance itself, it succeeds, and the server dutifully returns the instance's highly privileged, temporary IAM credentials to the attacker. Infrastructure Mitigation: While input validation is necessary, the defense-in-depth infrastructure fix is to enforce IMDSv2 (Instance Metadata Service Version 2) on the EC2 instances. IMDSv2 requires a specific PUT request containing a secret token header before it responds to any GET requests. A basic SSRF vulnerability typically only allows an attacker to forge simple GET requests, rendering the attack against the metadata service useless.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: This is a Server-Side Request Forgery (SSRF) attack. The attacker is tricking the server into making an HTTP request on their beha."
⚡ 60-Second Elevator Pitch Talking Points
  • Immediate Triage: This is a Server-Side Request Forgery (SSRF) attack. The attacker is tricking the server into m
  • Run targeted verification commands before modifying configuration.
  • Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement
Want more Security scenarios?
Explore our complete collection of scenario-based Security interview runbooks.
Browse All Security Questions →

📚 Related Production Scenarios in Security