
GIAC Cloud Penetration Tester
Domain 3Objective 3
Azure Functions and Windows Containers GCPN Practice Questions (Page 4)
Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
7concepts
Questions 16–20
- 16
A developer creates an Azure Function with an HTTP trigger that uses a third-party library to parse XML. The library is known to have a vulnerability that allows XXE (XML External Entity) attacks. The function is publicly accessible. What is the most effective way to mitigate this risk?
Select an answer first - 17
A developer deploys an Azure Function with an HTTP trigger that accepts a URL parameter and fetches that URL using an HttpClient. The function runs under a system-assigned managed identity. During a security review, you notice the function does not validate the URL and the managed identity has Contributor rights on a storage account containing sensitive data. Which combination of issues is the most immediate security concern?
Select an answer first - 18
Which of the following is a common vulnerability in Azure Functions that arises from using outdated or malicious open-source packages?
Select an answer first - 19
Which component of an Azure Functions app is responsible for connecting the function to external services such as Azure Storage queues or HTTP endpoints?
Select an answer first - 20
Which misconfiguration could allow a process inside a Windows container to gain elevated privileges on the host?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.