
GIAC Cloud Penetration Tester
Domain 3Objective 2
Microsoft Azure Cloud Services and Attacks GCPN Practice Questions (Page 6)
Part of the Cloud Platform Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
10concepts
Questions 26–30
- 26
A penetration tester has compromised an Azure AD user account that has 'Key Vault Contributor' role on a specific Key Vault. The Key Vault's access policy grants the user 'Get', 'List', and 'Set' permissions on secrets. What is the most significant risk to the organization?
Select an answer first - 27
A penetration tester has obtained valid credentials for a standard Azure AD user account through a phishing campaign. The user has no administrative roles, but the tester discovers the account has the 'Global Reader' role. During enumeration, the tester finds a custom RBAC role assignment at the subscription scope that grants the 'Microsoft.Authorization/roleAssignments/write' permission to a service principal owned by the same user. What is the most likely privilege escalation path the tester should pursue?
Select an answer first - 28
A penetration tester is assessing a client's Azure environment. The tester discovers that a user account with the 'Global Administrator' role has a weak password and no multi-factor authentication (MFA). The tester successfully password-sprays this account and signs in. Which of the following actions would be the MOST effective way to maintain persistent access while minimizing the chance of immediate detection?
Select an answer first - 29
A penetration tester has compromised an Azure AD account with 'Security Administrator' rights. The tester wants to avoid detection by security monitoring. Which of the following actions is the MOST effective way to evade detection?
Select an answer first - 30
A penetration tester is assessing an Azure DevOps pipeline that deploys to a production environment. The pipeline uses a variable group that references a secret from Azure Key Vault. The tester has 'Contributor' rights on the Azure DevOps project. Which of the following is the MOST effective way to exfiltrate the secret without triggering immediate alerts?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.