Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 7Objective 3

Cloud Penetration Testing CPENT Practice Questions (Page 2)

Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.

51questions here
11free pages
12concepts

Questions 6–10

  1. 6application · medium

    A healthcare organization uses AWS S3 to store patient records. They are required to comply with HIPAA. During a review, you find that the S3 bucket has server-side encryption enabled with AWS-managed keys (SSE-S3). What is the most important compliance gap you should identify?

    Select an answer first
  2. 7application · medium

    During the reconnaissance phase of a cloud penetration test, you are tasked with discovering any publicly exposed Azure Blob storage containers that belong to the target organization. Which technique is most effective for this purpose?

    Select an answer first
  3. 8foundation · easy

    Which cloud storage service is commonly associated with the term 'bucket'?

    Select an answer first
  4. 9application · medium

    A penetration tester is engaged to assess a healthcare organization's hybrid cloud environment. The organization uses an IaaS provider for production VMs and a SaaS application for patient scheduling. The tester has been granted permission to test the IaaS environment but not the SaaS application. During reconnaissance, the tester discovers that the SaaS application stores patient data in a cloud storage bucket that appears to be publicly accessible. What is the most appropriate action for the tester to take?

    Select an answer first
  5. 10expert · hard

    A company uses Azure Functions with a Consumption plan to process messages from a queue. The function triggers on new messages and writes results to a database. During a penetration test, you find that the function uses a connection string stored in the application settings, and the function app has 'Managed Identity' disabled. What is the most significant security weakness?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.