
GIAC Cloud Penetration Tester
Domain 2Objective 2
Cloud CLI and Application Mapping GCPN Practice Questions (Page 2)
Part of the Cloud Service Discovery and Reconnaissance domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
9concepts
Questions 6–10
- 6
You are mapping an API that uses OAuth 2.0 with client credentials. You have obtained the client ID and secret from a configuration file. You need to enumerate the API's endpoints and determine which ones require which scopes. Which approach is most effective?
Select an answer first - 7
During a GCP assessment, you have been granted `roles/viewer` on a project. You need to discover all APIs that are enabled in the project to understand the attack surface. Which gcloud command would you use?
Select an answer first - 8
What is the purpose of API discovery in penetration testing?
Select an answer first - 9
You are fingerprinting a web application that is behind a CDN. The CDN strips the `Server` header, but you need to identify the underlying framework. Which technique is most likely to reveal the framework?
Select an answer first - 10
What is the benefit of combining CLI enumeration with application mapping?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.