
GIAC Cloud Penetration Tester
Domain 1Objective 1
Cloud Penetration Testing Fundamentals GCPN Practice Questions (Page 1)
Part of the Cloud Penetration Testing Fundamentals domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
1concept
Questions 1–5
- 1
A penetration tester is planning a test for a client's GCP environment. The client wants to test the security of their Cloud SQL database and Cloud Storage bucket. The tester has been given the role of Cloud SQL Admin and Storage Admin. What is the primary objective of the test in this scenario?
Select an answer first - 2
A penetration tester is engaged to assess a client's multi-cloud environment that includes AWS and Azure. The client has a strict requirement that the test must not cause any disruption to production services. The tester needs to test the security of an S3 bucket and an Azure Blob storage container that contain sensitive data. Which approach best balances the need for thorough testing with the constraint of no disruption?
Select an answer first - 3
A cloud penetration tester is planning an assessment for a client's Azure environment. The client has a requirement that the test must not affect the availability of their production applications. The tester needs to test the security of an Azure App Service and an Azure SQL database. Which approach is most appropriate to meet the availability constraint?
Select an answer first - 4
A cloud penetration tester is assessing a client's GCP environment. The client has a requirement that the test must be completed within a limited time frame and with minimal cost. The tester needs to test the security of a Compute Engine instance and a Cloud SQL database. The tester has been given Owner IAM permissions. Which approach is most efficient and cost-effective while still providing a meaningful assessment?
Select an answer first - 5
A penetration tester is engaged to assess a client's AWS environment. The client has a compliance requirement that the test must not involve any activity that could be considered a denial-of-service attack. The tester needs to test the security of an EC2 instance that hosts a critical application. Which testing technique is most appropriate under this constraint?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.