
GIAC Cloud Penetration Tester
Domain 3Objective 3
Azure Functions and Windows Containers GCPN Practice Questions (Page 3)
Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
7concepts
Questions 11–15
- 11
During a red team exercise, a tester gains code execution inside a Windows container running on AKS. The container is running with process isolation and has a mount of the host's Docker socket. The tester wants to escape to the host. Which technique is most likely to succeed?
Select an answer first - 12
An AKS cluster runs Windows containers with a pod security policy that restricts privileged containers. The security team wants to prevent container escape via the Docker socket. However, a legacy application requires access to the host's Docker daemon for management. Which solution best balances security and the application's requirement?
Select an answer first - 13
In a Windows container using process isolation, what is shared between the container and the host operating system?
Select an answer first - 14
In an AKS cluster running Windows containers, you discover that the cluster's kubelet is configured with `--anonymous-auth=true` and the node's firewall allows access from the internet. An attacker has network access to the kubelet port. Which attack is the most immediate risk?
Select an answer first - 15
Which defensive strategy is most effective in limiting the impact of a compromised Azure Function?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.