Hands-on cloud skills · live AWS environments

Build skills that survive the incident.

Practice real recovery workflows in temporary AWS accounts. Diagnose the failure, contain the threat, restore service and measure the outcome.

Lab library

Choose what to practise next

Browse production-shaped scenarios across recovery, security and operations.

Loading labs…Self-paced · Temporary AWS access
Scenario briefing

Recover a Critical Air Traffic Control Service

Your Role

You are part of the NATS Infrastructure Team, responsible for supporting a critical air traffic control system used across UK airports to track and manage flights.

Without warning—10–15 minutes after the lab launches—the system goes down.

Flights are grounded. Aircraft already in the air are managed using contingency procedures. Disruption spreads rapidly across UK airports.

Every minute counts.

The outage causes escalating operational disruption, significant financial losses and increasing pressure from airlines, airports and senior leadership.

The Mission

Get the service back online—FAST.

But there is a catch: restoring immediately could give the attacker another system to destroy.

Your team must:

The Infrastructure

The application is fronted by an Amazon Application Load Balancer. The application runs on EC2 with a DynamoDB backend. Daily backups exist for both EC2 and DynamoDB. The ALB and EC2 application each use their own security group.

Architecture

Air Traffic Control lab architecture showing the load balancer, two EC2 instances and DynamoDB

Scaling is not supported in this lab.
The environment uses a fixed two-instance architecture and does not include an Auto Scaling group.

If you think you have finished, head to the monitoring page and click the green button which should appear at the top (If you have completed the lab)

Access within the account is limited to the permissions needed to recover the service.

Recovery support

Incident response hints

Use these prompts if your recovery has stalled:

Public leaderboard

Choose your participant nickname

Your nickname will identify your score and downtime on the public lab leaderboard.

Use a nickname only.
Do not enter your email address, full name or other personal information.

2–24 characters. Letters, numbers, spaces, hyphens and underscores only.

End lab early

This attempt will not be scored

Ending now permanently closes the AWS environment and removes all lab resources and access.

No score or assessment will be recorded.
This attempt will not appear on the leaderboard.

Your purchase includes two attempts. If you have another attempt remaining, you can end this session and launch the lab again. Press Continue only if you are ready to finish.