Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Penetration Tester

Domain 1Objective 1

Cloud Penetration Testing Fundamentals GCPN Practice Questions (Page 4)

Part of the Cloud Penetration Testing Fundamentals domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
1concept

Questions 16–20

  1. 16application · medium

    A penetration tester is assessing a cloud environment that uses a database-as-a-service (DBaaS) offering. The client wants to test the security of the database. Which testing activity is most appropriate?

    Select an answer first
  2. 17application · medium

    A cloud penetration tester is assessing a cloud environment that uses a content delivery network (CDN) to serve static content. The client wants to test the security of the CDN configuration. Which testing activity is most appropriate?

    Select an answer first
  3. 18expert · hard

    A cloud penetration tester is assessing a multi-account AWS environment. The client wants to test the security of the organization's control tower and guardrails. The tester has been given read-only access to the management account and full access to a member account. Which testing approach is most effective?

    Select an answer first
  4. 19expert · hard

    A penetration tester is assessing a cloud environment that uses a shared responsibility model. The client wants to test the security of the entire stack, from the application down to the physical infrastructure. The client has a limited budget and time. Which testing approach is most appropriate?

    Select an answer first
  5. 20expert · hard

    A penetration tester is contracted to assess a cloud environment that hosts a critical application. The client has two constraints: the assessment must not cause any downtime, and the tester must identify vulnerabilities that could be exploited by an external attacker. The application is behind a Web Application Firewall (WAF) and a load balancer. Which testing approach best balances these constraints?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.