Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 8Objective 3

Cloud Hacking Methodology CEH Practice Questions (Page 2)

Part of the Cloud Computing domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~7–11 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
10concepts

Questions 6–10

  1. 6application · medium

    A security team suspects that an attacker has compromised a cloud account by stealing a user's OAuth token. The attacker used the token to access cloud resources and then created a new service principal with elevated privileges. Which phase of the cloud hacking methodology does the creation of the service principal represent?

    Select an answer first
  2. 7application · medium

    A security analyst is performing cloud reconnaissance against a target organization. The analyst discovers a publicly accessible Azure Blob storage container that lists the organization's internal project names. Which technique was used to discover this information?

    Select an answer first
  3. 8application · medium

    A security auditor is reviewing a client's Azure environment and finds a Storage Account with a container that has 'Container access level' set to 'Public blob'. The auditor also notes that the storage account's firewall is configured to 'Enabled from selected networks' but the 'Allow trusted Microsoft services' exception is checked. Which action represents the MOST direct exploitation of this misconfiguration?

    Select an answer first
  4. 9application · medium

    A penetration tester has compromised an Azure VM and obtained the managed identity credentials. The tester wants to escalate privileges to the subscription level. Which technique is most appropriate?

    Select an answer first
  5. 10application · medium

    During a cloud security assessment, a tester finds that an Azure Storage account has a container with 'Blob' anonymous read access enabled. The tester also notices that the storage account's shared access signature (SAS) token is embedded in a public GitHub repository. Which action should the tester take to demonstrate the most critical risk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.