
GIAC Cloud Penetration Tester
Domain 3Objective 1
AWS Authentication and Cloud Services GCPN Practice Questions (Page 1)
Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
Questions 1–5
- 1
A security engineer is reviewing IAM policies and finds that a user has a policy that allows 'iam:CreateAccessKey' on their own user. What is the primary security concern?
Select an answer first - 2
A security team discovers that an IAM role in their AWS account has a trust policy that allows 'sts:AssumeRole' from 'Principal': {'AWS': 'arn:aws:iam::123456789012:root'}. The external account 123456789012 is not a partner or vendor. What is the primary risk?
Select an answer first - 3
A security auditor is reviewing an IAM policy that allows 'ec2:RunInstances' and 'iam:PassRole' on all resources. The auditor wants to prevent a user from launching an EC2 instance with a role that has administrative privileges. Which additional policy statement would achieve this?
Select an answer first - 4
Which AWS authentication method is most appropriate for an external identity provider (IdP) such as Okta or Active Directory to grant users access to AWS resources?
Select an answer first - 5
Which AWS authentication mechanism is specifically designed to grant temporary, scoped access to a user or application without requiring the creation of a long-lived IAM user?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.