
GIAC Cloud Penetration Tester
Domain 3Objective 1
AWS Authentication and Cloud Services GCPN Practice Questions (Page 3)
Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
Questions 11–15
- 11
In an IAM policy, what does the "Effect" element specify?
Select an answer first - 12
During an engagement, a tester finds a set of AWS access keys in a public GitHub repository. The keys belong to an IAM user with 's3:ListBucket' and 's3:GetObject' permissions on a specific bucket. The tester wants to verify the keys are still active and determine what data is exposed. Which approach is the MOST appropriate?
Select an answer first - 13
A penetration tester has obtained temporary credentials from an assumed role. The credentials have a session token. Which AWS service call would the tester use to determine the exact role name and account ID associated with these credentials?
Select an answer first - 14
A security team wants to monitor API calls made by a specific IAM user in their AWS account. They need to capture the source IP address, user agent, and the exact API action. Which AWS service should they use?
Select an answer first - 15
A penetration tester obtains a set of temporary AWS credentials from a compromised developer workstation. The credentials are in the form of an access key ID, secret access key, and session token. Which AWS service is most likely to have issued these credentials?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.