Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cloud Security Engineer

Domain 4Objective 1

Penetration Testing in Cloud CCSE Practice Questions (Page 9)

Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.

52questions here
11free pages
9concepts

Questions 41–45

  1. 41expert · hard

    A penetration tester is hired to test a public cloud environment that is part of a hybrid deployment. The tester has received written authorization from the client, but the client's cloud provider has a policy that requires pre-approval for certain types of tests. What should the tester do?

    Select an answer first
  2. 42expert · hard

    During a cloud penetration test, a tester discovers that a cloud function (serverless) has an overly permissive IAM role that allows it to invoke other functions and read from a database. The tester has authorization to test the environment. What is the most effective way to demonstrate the impact of this misconfiguration?

    Select an answer first
  3. 43foundation · easy

    Which of the following is a common cloud-specific attack vector?

    Select an answer first
  4. 44foundation · easy

    What is a common attack vector related to identity and access management (IAM) in the cloud?

    Select an answer first
  5. 45application · medium

    During the exploitation phase of a cloud penetration test, a tester successfully compromises an IAM user's access keys. What is the most appropriate post-exploitation action to demonstrate impact without causing damage?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.