Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Penetration Tester

Domain 3Objective 3

Azure Functions and Windows Containers GCPN Practice Questions (Page 5)

Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
7concepts

Questions 21–25

  1. 21foundation · easy

    Which of the following is a recommended defensive measure to secure Windows containers running in Azure?

    Select an answer first
  2. 22application · medium

    Your organization is deploying an Azure Function that handles credit card numbers. The function is triggered by an HTTP request and stores data in a Cosmos DB database. You need to ensure that the function's code does not contain hardcoded secrets and that the function can only access the Cosmos DB account. What should you do?

    Select an answer first
  3. 23expert · medium

    An organization runs Windows containers on AKS using a custom VNet. The AKS cluster has an API server that is publicly accessible. The security team wants to reduce the attack surface without losing the ability to manage the cluster from a jump box. Which combination of controls would best achieve this?

    Select an answer first
  4. 24application · medium

    An Azure Function with a Blob trigger is configured with a system-assigned managed identity that has Storage Blob Data Contributor on the storage account. An attacker has found a way to upload a blob that causes the function to execute arbitrary code. What is the most likely impact the attacker can achieve?

    Select an answer first
  5. 25application · medium

    A company runs an Azure Function app with an HTTP trigger that processes user-supplied URLs and fetches them server-side. During a review, the security team notes that the function has a system-assigned managed identity with Contributor rights on a storage account. An attacker who can invoke the function could potentially read the storage account's access keys. Which single configuration change would most directly reduce the impact of an SSRF vulnerability in this function?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.