
GIAC Cloud Penetration Tester
Domain 3Objective 2
Microsoft Azure Cloud Services and Attacks GCPN Practice Questions (Page 4)
Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
10concepts
Questions 16–20
- 16
In Azure AD, which object is an application identity that can be assigned permissions and used by applications to authenticate to Azure resources without a user?
Select an answer first - 17
During an Azure penetration test, you gain access to a virtual machine (VM) that is part of a VNet with no public IP. The VM has a managed identity assigned. You need to pivot to other resources in the same VNet. Which of the following is the MOST effective technique to discover and access other resources?
Select an answer first - 18
Which Azure VM feature provides a REST endpoint accessible from within the VM that can expose managed identity tokens and other instance-specific information?
Select an answer first - 19
In Azure DevOps, which component is used to connect a pipeline to external services, such as Azure subscriptions or GitHub, and can be abused if credentials are overly permissive?
Select an answer first - 20
A penetration tester has compromised an Azure VM and discovers that the VM has a managed identity with 'Storage Blob Data Reader' role on a storage account. Which of the following is the MOST effective way to exfiltrate data from the storage account?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.