Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Penetration Tester

Domain 1Objective 1

Cloud Penetration Testing Fundamentals GCPN Practice Questions (Page 6)

Part of the Cloud Penetration Testing Fundamentals domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
1concept

Questions 26–30

  1. 26application · medium

    A penetration tester is assessing a multi-cloud environment that includes AWS and Azure. The tester has been asked to evaluate the security of the identity and access management (IAM) configurations in both clouds. Which approach best aligns with the objectives of cloud penetration testing?

    Select an answer first
  2. 27application · medium

    A penetration tester is planning a test for a client's AWS environment. The client wants to test the security of their Lambda functions and API Gateway endpoints. The tester has been given IAM credentials with permissions to invoke Lambda functions and access API Gateway. What is the primary objective of the test in this scenario?

    Select an answer first
  3. 28application · medium

    A penetration tester is assessing a client's GCP environment. The client wants to test the security of their Cloud Functions and Cloud Run services. The tester has been given the role of Cloud Functions Admin and Cloud Run Admin. What is a key consideration when testing serverless services like Cloud Functions and Cloud Run?

    Select an answer first
  4. 29application · medium

    A company is moving its on-premises data center to a public cloud. The security team wants to conduct a penetration test of the new cloud environment. They have a traditional on-premises testing methodology that includes physical security checks and network sniffing on the local LAN. Which adjustment is most important when adapting the methodology to the cloud?

    Select an answer first
  5. 30expert · hard

    A penetration tester is assessing a cloud environment that uses a private cloud on dedicated hardware. The client wants to test the security of the hypervisor and the physical network. The tester has been given administrative access to the hypervisor management console. Which testing approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCPN

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.