
EC-CouncilCertified Ethical Hacker
Domain 8Objective 3
Cloud Hacking Methodology CEH Practice Questions (Page 4)
Part of the Cloud Computing domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~7–11 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
10concepts
Questions 16–20
- 16
Which cloud privilege escalation technique involves modifying the trust policy of an IAM role to allow an attacker-controlled account to assume it?
Select an answer first - 17
A security engineer is reviewing the configuration of an AWS account and finds that an S3 bucket has a bucket policy that allows 's3:GetObject' for any principal ('*'). The engineer also notices that the bucket is not publicly accessible via the static website hosting endpoint. Which of the following is the MOST likely risk associated with this configuration?
Select an answer first - 18
In the cloud hacking methodology, which phase typically follows initial reconnaissance and involves actively probing discovered cloud services for vulnerabilities?
Select an answer first - 19
A security analyst is investigating a potential cloud credential attack. The analyst notices that a legitimate user's access key was used to create a new IAM user with administrative privileges, and then the original user's key was rotated. The activity occurred outside business hours. Which attack technique is most likely being used?
Select an answer first - 20
During a red team exercise, a tester has compromised a low-privileged user account in a GCP project. The tester discovers that the user has the 'roles/iam.securityReviewer' role on the project. Which technique is the MOST effective for the tester to escalate privileges?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.