Categories//ntrol/API Key Exposure

API Key Exposure

intermediate8 min100 pts

Your security scanner just fired an alert. A config file with what looks like credentials was pushed to a public repository.

We need a full audit of what's exposed and severity assessment. The clock is ticking.

What you're being evaluated on

Identifying all secrets - Every hardcoded credential, key, and token.
Severity assessment - Which keys give the most dangerous access?
Understanding blast radius - What can an attacker do with each exposed credential?

3 hints available (using hints reduces your score)

About this scenario

A config file was committed to a public repo 4 minutes ago. How bad is it? Your security scanner just fired an alert. A config file with what looks like credentials was pushed to a public repository.

intermediate · 100 points · 8 min · PII & Security

What you will practice

Play the full scenario above for free. More PII & Security scenarios · Create a free account to save your progress.