Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 7Objective 3

Cloud Penetration Testing CPENT Practice Questions (Page 9)

Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.

51questions here
11free pages
12concepts

Questions 41–45

  1. 41application · medium

    After a security incident in a Google Cloud Platform (GCP) project, you need to determine if any unauthorized actions were performed by a compromised service account. You have access to Cloud Logging. What is the most effective way to identify the actions taken by this specific service account?

    Select an answer first
  2. 42foundation · easy

    Which of the following is a key gap in cloud logging that can hinder incident response?

    Select an answer first
  3. 43application · medium

    A company uses AWS Lambda functions to process user-uploaded images. The function takes an image URL from an API request, downloads it, and stores it in an S3 bucket. During a penetration test, you find that the function does not validate the URL and uses the 'requests' library to fetch it. What is the most likely vulnerability an attacker could exploit?

    Select an answer first
  4. 44expert · hard

    You are conducting a penetration test on a GCP environment. You find a Compute Engine VM with a public IP and a firewall rule allowing TCP port 22 (SSH) from the entire internet (0.0.0.0/0). The VM has a service account with 'roles/compute.instanceAdmin' at the project level. What is the most critical risk you should report?

    Select an answer first
  5. 45foundation · easy

    Which of the following is a common injection flaw in serverless functions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.