
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 3
Cloud Penetration Testing CPENT Practice Questions (Page 7)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
51questions here
11free pages
12concepts
Questions 31–35
- 31
Which compliance framework is specifically designed for cloud service providers and includes controls for data protection and privacy?
Select an answer first - 32
Which of the following is a common cloud-specific threat that arises when a storage bucket is configured to allow public read access?
Select an answer first - 33
A security tester is evaluating a cloud-based API that uses OAuth 2.0 with the 'client_credentials' grant. The API is used by multiple internal services. The tester discovers that the API's scope validation is weak and allows a client to request any scope, including 'admin'. What is the most likely impact?
Select an answer first - 34
During an authorized penetration test of a hybrid cloud environment, you discover a virtual machine (VM) in a public cloud VNet that has a public IP address and an attached network security group (NSG) allowing inbound RDP (port 3389) from the internet. The VM is part of a domain-joined workload and hosts a legacy application. Your client wants to know the most likely initial attack vector an external attacker would use to compromise this VM. What is the most probable attack path?
Select an answer first - 35
You are testing a Kubernetes cluster deployed in a public cloud. The cluster uses a network policy that allows all ingress traffic to pods in the 'frontend' namespace. A developer asks you to restrict access so only the 'api-gateway' service can reach the frontend pods. What should you recommend?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.