
GIAC Cloud Penetration Tester
Domain 3Objective 1
AWS Authentication and Cloud Services GCPN Practice Questions (Page 2)
Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
Questions 6–10
- 6
A penetration tester is reviewing an IAM policy that allows 's3:GetObject' on 'arn:aws:s3:::example-bucket/*'. The tester wants to escalate privileges by using this permission. Which technique would be MOST effective?
Select an answer first - 7
A penetration tester is investigating a compromised EC2 instance. The instance has an IAM role attached. The tester wants to use the instance's credentials to access other AWS services. Which of the following is the most reliable method to obtain the credentials?
Select an answer first - 8
An IAM policy includes the following statement: 'Effect': 'Allow', 'Action': 'ec2:*', 'Resource': '*'. A security reviewer wants to limit the risk of privilege escalation via EC2. Which additional IAM permission should be explicitly denied to prevent a common escalation path?
Select an answer first - 9
A developer accidentally committed AWS access keys to a public GitHub repository. The keys are for an IAM user with 'ec2:DescribeInstances' and 's3:ListBucket' permissions. What is the FIRST step the developer should take to mitigate the exposure?
Select an answer first - 10
A penetration tester is investigating a potential credential leak. The tester finds an access key ID that starts with 'ASIA' and a session token. The tester wants to determine the expiration time of these credentials. Which action would provide that information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.