
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 3
Cloud Penetration Testing CPENT Practice Questions (Page 8)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
51questions here
11free pages
12concepts
Questions 36–40
- 36
You are testing a REST API deployed on Azure API Management. The API uses OAuth 2.0 with client credentials grant. You notice that the API returns detailed error messages, including stack traces, when an invalid token is provided. What is the most significant security issue?
Select an answer first - 37
A cloud security team is reviewing their logging configuration. They have enabled CloudTrail in AWS, but they notice that S3 data events are not being logged. They are concerned about missing visibility into unauthorized access to sensitive objects. What is the best recommendation?
Select an answer first - 38
Which component of a container orchestration platform is responsible for managing the desired state of the cluster?
Select an answer first - 39
Which of the following is a common API-level attack that targets the authentication mechanism?
Select an answer first - 40
Which phase of a cloud penetration test involves obtaining permission from the cloud provider?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.