
GIAC Cloud Penetration Tester
Domain 3Objective 2
Microsoft Azure Cloud Services and Attacks GCPN Practice Questions (Page 2)
Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
10concepts
Questions 6–10
- 6
A penetration tester is assessing an Azure App Service that uses Azure AD authentication. The tester discovers that the App Service has a 'staging' slot that is not protected by authentication. Which of the following is the MOST effective way to exploit this misconfiguration?
Select an answer first - 7
Which Azure service is used to collect and analyze telemetry data, such as metrics, logs, and application insights, and is a common target for attackers to disable or manipulate to evade detection?
Select an answer first - 8
Which Azure networking component is used to establish a site-to-site VPN connection between an on-premises network and an Azure virtual network?
Select an answer first - 9
Which Azure serverless service is primarily used to run event-driven code without managing infrastructure, and can be vulnerable to code injection if user input is not properly handled?
Select an answer first - 10
A penetration tester is assessing an Azure environment where a VM has a public IP and is protected by an NSG that allows inbound RDP (port 3389) from 'Internet' (0.0.0.0/0). The tester wants to gain initial access. Which of the following is the MOST direct attack vector?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.