
GIAC Cloud Penetration Tester
Domain 1Objective 1
Cloud Penetration Testing Fundamentals GCPN Practice Questions (Page 2)
Part of the Cloud Penetration Testing Fundamentals domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
1concept
Questions 6–10
- 6
A cloud penetration tester is assessing a client's Azure environment. The client wants to test the security of their Azure Kubernetes Service (AKS) cluster and Azure Container Registry (ACR). The tester has been given Contributor permissions on the AKS cluster and ACR. What is a key consideration when testing containerized workloads in the cloud?
Select an answer first - 7
A penetration tester is assessing a Google Cloud Platform (GCP) project. The tester needs to test the security of a Compute Engine instance that hosts a web application. The tester has been given Owner IAM permissions on the project. What is the most important consideration when planning the test to avoid violating GCP's terms of service?
Select an answer first - 8
A cloud penetration tester is planning an assessment for a client's GCP environment. The client wants to test the security of their Kubernetes Engine (GKE) cluster and Cloud Storage buckets. The tester has been given the role of Security Reviewer on the project. What is the primary objective of the penetration test in this scenario?
Select an answer first - 9
A cloud penetration tester is assessing a serverless application that uses AWS Lambda and API Gateway. The client wants to test the security of the application, but the tester has no access to the Lambda function code. The tester only has the API endpoint URL and a set of test credentials. Which testing approach is most effective?
Select an answer first - 10
A security consultant is conducting a penetration test for a client's AWS environment. The client wants to test the security of their S3 buckets and EC2 instances. The consultant has been granted IAM credentials with read-only access to the account. Which of the following is a key difference between cloud penetration testing and traditional on-premises testing that the consultant must account for?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.