Skip to content

Sample report. Every candidate and score below is fictional, shown to illustrate what employers receive. Real reports are private, per-assessment secret links. Want to feel where these scores come from? Try the assessment yourself.

Assessment report

Cloud Security Engineer — S3 & IAM Hardening

s3-misconfiguration-auditCreated Jul 2, 2026
Role: Cloud Security EngineerLevel: Mid-level (2–5 yrs)Time limit: 60 minEnvironment: Real AWS account — isolated per candidate, auto-wiped

At a glance

Priya S. leads with 6 of 6 checks passed, in 41 of 60 min.

4 of 6 invited completed the assessment. Verified scores ranged 33% to 100% (avg 71%), and 1 candidate passed every check across all four competencies.

6
Invited
4/6
Submitted
71%
Avg correctness
55 min
Median time
3/4
With reflection

How this is scored. Every check below is verified against the live cloud environment each candidate worked in. Scoring reflects objective, measured outcomes only — we don’t infer soft skills or apply a hire / no-hire verdict.

4 of 4 shown

Swipe the table sideways for correctness, time and reflection.

RankCandidate & competenciesChecksCorrectnessTime usedStatusReflectionReport
Rank 1
Priya S.
Cloud Security Engineer
Objective correctness1/1Security rigor3/3No new exposure1/1Operational safety1/1
6 / 6
100%
41 min / 60SubmittedReflection submittedView →
Rank 2
Ananya K.
Cloud Security Engineer
Objective correctness1/1Security rigor2/3No new exposure1/1Operational safety1/1
5 / 6
83%
52 min / 60SubmittedReflection submittedPrivate link
Rank 3
Rahul M.
Cloud Security Engineer
Objective correctness1/1Security rigor2/3No new exposure0/1Operational safety1/1
4 / 6
67%
58 min / 60SubmittedReflection submittedPrivate link
Rank 4
Vikram T.
Cloud Security Engineer
Objective correctness0/1Security rigor2/3No new exposure0/1Operational safety0/1
2 / 6
33%
60 min / 60SubmittedPrivate link

Candidates are ranked by verified performance on a real, isolated AWS environment — not a quiz. On a live report, every row links to that candidate's full private breakdown — the first one is expanded below.

Inside a candidate's report

Candidate report

Priya S.

Cloud Security Engineer · Completed in 41 of 60 min · Graded Jul 2, 2026

Verified checks passed

6/ 6checks passed
100%

Competency profile

6/6 checks passed

Objective correctness

Reached the required secure end-state — the core task.

1/1
  • Public read access blocked on all data bucketsPassed

Security rigor

Hardened properly: least privilege and defence in depth, not just the minimum.

3/3
  • Over-broad s3:* on the auditor IAM user scoped to least privilegePassed
  • Server-side encryption enforced (unencrypted uploads denied)Passed
  • TLS required — non-HTTPS requests denied by bucket policyPassed

No new exposure

Closed the issue without leaving or opening another way in.

1/1
  • No bucket policy grants a wildcard (anonymous) principalPassed

Operational safety

Secured the workload in place — didn't delete or break it to clear the alert.

1/1
  • Buckets secured in place — not deleted to clear the findingPassed

Written reflection

The candidate's own 3–5 sentence account of what they found and how they fixed it — proof they understood the problem, not just clicked through it.

The data bucket was public and unencrypted, and the pipeline user had s3:* on all resources. I blocked public access at the account and bucket level, enforced SSE-KMS, and added a TLS-only bucket policy. For IAM, I replaced the wildcard with the five actions the pipeline actually uses, scoped to the bucket ARN, and detached the admin policy so a leaked key can't escalate.

This is what you get for every candidate.

Send a link, the candidate solves a real cloud security task in an isolated AWS account, and you get a verified, side-by-side report. No résumé guesswork.