
EC-CouncilCertified Cloud Security Engineer
Domain 4Objective 1
Penetration Testing in Cloud CCSE Practice Questions (Page 9)
Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.
52questions here
11free pages
9concepts
Questions 41–45
- 41
A penetration tester is hired to test a public cloud environment that is part of a hybrid deployment. The tester has received written authorization from the client, but the client's cloud provider has a policy that requires pre-approval for certain types of tests. What should the tester do?
Select an answer first - 42
During a cloud penetration test, a tester discovers that a cloud function (serverless) has an overly permissive IAM role that allows it to invoke other functions and read from a database. The tester has authorization to test the environment. What is the most effective way to demonstrate the impact of this misconfiguration?
Select an answer first - 43
Which of the following is a common cloud-specific attack vector?
Select an answer first - 44
What is a common attack vector related to identity and access management (IAM) in the cloud?
Select an answer first - 45
During the exploitation phase of a cloud penetration test, a tester successfully compromises an IAM user's access keys. What is the most appropriate post-exploitation action to demonstrate impact without causing damage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.