
GIAC Cloud Penetration Tester
Domain 3Objective 3
Azure Functions and Windows Containers GCPN Practice Questions (Page 2)
Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
7concepts
Questions 6–10
- 6
What is a primary reason why Windows containers in AKS may have a larger attack surface compared to Linux containers?
Select an answer first - 7
Which technique is commonly used to exploit an Azure Function that passes user input directly to a system shell command?
Select an answer first - 8
A penetration tester is assessing an Azure Function app that uses multiple triggers: an HTTP trigger, a Service Bus queue trigger, and a Blob trigger. The function app has a single code base that handles all triggers. The tester discovers that the HTTP trigger is vulnerable to SSRF. Which factor most significantly increases the attack surface compared to having only an HTTP trigger?
Select an answer first - 9
Which of the following is a potential method to escape a Windows container?
Select an answer first - 10
A company uses Azure Functions for a critical API. The security team wants to monitor for suspicious activity, such as unusual trigger invocations or attempts to access sensitive bindings. Which combination of Azure services would provide the most comprehensive monitoring and alerting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.