Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 7Objective 3

Cloud Penetration Testing CPENT Practice Questions (Page 4)

Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.

51questions here
11free pages
12concepts

Questions 16–20

  1. 16foundation · easy

    Which of the following is a governance risk in cloud environments?

    Select an answer first
  2. 17foundation · easy

    Which of the following is a common vulnerability in container images that can be exploited during a penetration test?

    Select an answer first
  3. 18application · medium

    As part of a cloud penetration test, you are assessing an AWS environment. You find an S3 bucket that is supposed to contain internal financial reports. The bucket policy allows 's3:GetObject' to 'Principal: *' but only from a specific IP range (203.0.113.0/24). Your client's office uses that IP range. What is the most significant security issue with this configuration?

    Select an answer first
  4. 19expert · hard

    After a security incident in an AWS account, you need to determine if an attacker exfiltrated data from an S3 bucket. You have CloudTrail enabled, but you are unsure if it captured all relevant events. What is the most important factor to verify to ensure you can detect the exfiltration?

    Select an answer first
  5. 20application · medium

    A penetration tester is assessing a government contractor's cloud environment that must comply with FedRAMP. The contractor uses a public cloud provider and has implemented strong IAM policies and encryption. However, the tester finds that the cloud provider's data center is located in a foreign country. What is the most likely compliance issue?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.