
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 3
Cloud Penetration Testing CPENT Practice Questions (Page 6)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
51questions here
11free pages
12concepts
Questions 26–30
- 26
Which IAM misconfiguration allows a user to grant themselves additional permissions beyond those originally assigned?
Select an answer first - 27
What is a recommended improvement for cloud monitoring to enhance detection of suspicious activities?
Select an answer first - 28
A penetration tester is testing an AWS Lambda function that processes user-supplied JSON data and stores results in an S3 bucket. The function uses the 'boto3' library to interact with S3. The tester discovers that the function's IAM role has 's3:PutObject' permission on a bucket that contains sensitive data. What is the most likely attack vector?
Select an answer first - 29
You are assessing a Kubernetes cluster on Amazon EKS. The cluster uses a node group with the 'AmazonEKSWorkerNodePolicy' and the nodes are in a private subnet. The cluster has a load balancer that exposes a web application to the internet. You discover that the web application pod has a service account that can list secrets in the cluster. What is the most significant risk?
Select an answer first - 30
A large enterprise uses a multi-cloud strategy with AWS and Azure. They have a critical application that uses an AWS IAM role to access an Azure SQL database. The IAM role has a trust policy that allows the Azure AD application to assume it. During a penetration test, you discover that the Azure AD application has the 'Global Administrator' role. What is the most significant security risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.