Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Penetration Tester

Domain 6Objective 1

Password Attacks on Cloud Environments GCPN Practice Questions (Page 8)

Part of the Credential Attacks and Evasion domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
8concepts

Questions 36–40

  1. 36application · medium

    An organization uses Azure AD with federation to an on-premises ADFS server. A penetration tester discovers that the ADFS server has a weak token-signing certificate. Which attack is the tester most likely to execute?

    Select an answer first
  2. 37application · medium

    A penetration tester is evaluating the security of a cloud application. The tester has a list of usernames and wants to test if any users have weak passwords. The application does not have lockout policies but does have rate limiting per IP. Which attack method is most appropriate?

    Select an answer first
  3. 38application · medium

    A penetration tester is performing a brute force attack against a web application that uses Azure AD for authentication. The application has a lockout policy of 10 failed attempts per 15 minutes per user. The tester wants to test a list of 100 passwords for a single known username without locking the account. Which strategy is most effective?

    Select an answer first
  4. 39expert · hard

    A security team is investigating a breach where attackers accessed cloud accounts using credentials from a previous breach. The accounts did not have MFA. The team wants to implement a control that specifically addresses credential stuffing without requiring MFA for every login. Which control is most effective?

    Select an answer first
  5. 40application · medium

    A security analyst is reviewing logs after a suspected credential stuffing attack against the company's SaaS application. The application uses an email address and password for login and does not enforce MFA. The analyst sees thousands of failed login attempts from various IP addresses, but a few succeed. Which combination of findings most strongly indicates credential stuffing rather than a simple brute force attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.