Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Penetration Tester

Domain 2Objective 2

Cloud CLI and Application Mapping GCPN Practice Questions (Page 3)

Part of the Cloud Service Discovery and Reconnaissance domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
9concepts

Questions 11–15

  1. 11foundation · easy

    Which HTTP method is typically used to retrieve information from an API endpoint?

    Select an answer first
  2. 12application · medium

    A cloud penetration tester is assessing an Azure subscription and needs to discover which services are available in a specific region (e.g., East US) to understand the attack surface. The tester has authenticated with the Azure CLI. Which command should the tester run to list the available services in that region?

    Select an answer first
  3. 13expert · hard

    A penetration tester is mapping a microservices-based application on AWS. The application uses Amazon ECS with Fargate, an Application Load Balancer (ALB), and an RDS database. The tester needs to identify the ECS services, the tasks running behind the ALB, and the database connections. The tester has read-only access to ECS, ELBv2, and RDS. Which sequence of AWS CLI commands would be most efficient?

    Select an answer first
  4. 14application · medium

    You are mapping a web application hosted on an AWS EC2 instance behind an Application Load Balancer. The application appears to be a custom API. You need to identify the underlying web server and framework versions without triggering intrusive scans. Which technique is most appropriate?

    Select an answer first
  5. 15expert · hard

    You are conducting a penetration test of an AWS environment. You have been given two sets of credentials: one for a read-only user in the production account and one for an admin user in a separate 'security' account. You need to enumerate resources in the production account, but the read-only user can only assume a role in the production account. Which approach should you use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.