
EC-CouncilCertified Ethical Hacker
Domain 8Objective 3
Cloud Hacking Methodology CEH Practice Questions (Page 9)
Part of the Cloud Computing domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~7–11 in this domain), expect 2–3 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
10concepts
Questions 41–45
- 41
An attacker has compromised an EC2 instance in a private subnet within a VPC. The instance has an IAM role attached that only allows 's3:GetObject' on a specific bucket. The attacker wants to move laterally to an RDS database in the same VPC. Which of the following is the MOST viable lateral movement technique?
Select an answer first - 42
Why do attackers modify IAM policies to establish persistence in a cloud environment?
Select an answer first - 43
What is a common result of exploiting an overly permissive IAM policy in a cloud environment?
Select an answer first - 44
A penetration tester is starting a cloud assessment for a client that uses a multi-cloud environment (AWS and Azure). The tester has been given no credentials and must begin from an external perspective. Which of the following is the MOST appropriate first step in the cloud hacking methodology?
Select an answer first - 45
Which cloud persistence mechanism involves creating a new user account with administrative privileges?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.