
CompTIAPenTest+
Domain 4Objective 5
Cloud-Based Attacks PT0-003 Practice Questions (Page 1)
Part of the Attacks and exploits domain, which accounts for 35% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~23–39 in this domain), expect 4–7 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
6concepts
35%of the exam
Questions 1–5
- 1
What is the purpose of using IAM roles instead of long-term access keys for applications running on cloud instances?
Select an answer first - 2
A security analyst is reviewing IAM policies in AWS. They find a policy that allows a user to list all S3 buckets but not read or write objects. What is the most likely risk associated with this policy?
Select an answer first - 3
A DevOps team is deploying containers to a Kubernetes cluster. They want to reduce the risk of container escape attacks. Which configuration should they implement?
Select an answer first - 4
Which technique is commonly used to escape a containerized environment by exploiting a misconfigured capability that allows the container process to interact with the host kernel?
Select an answer first - 5
A penetration tester is assessing a containerized application. The tester finds that the container has the CAP_SYS_ADMIN capability and is running as root. Which technique is most likely to achieve a container escape?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.