
GIAC Cloud Penetration Tester
Domain 1Objective 2
Red Team Penetration Testing of Cloud Environments GCPN Practice Questions (Page 4)
Part of the Cloud Penetration Testing Fundamentals domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
11concepts
Questions 16–20
- 16
What is the primary purpose of a red team report?
Select an answer first - 17
You are assessing a Kubernetes cluster in a cloud environment. You have obtained read-only access to the cluster's API server. Which action is most likely to lead to code execution in a pod?
Select an answer first - 18
A red team operator has compromised a cloud environment and wants to maintain access without being detected. The environment has centralized logging enabled, and the security team monitors for unusual API calls. Which technique is most effective for evading detection while maintaining persistence?
Select an answer first - 19
After completing a cloud red team engagement, the team is preparing the final report. The client's stakeholders include both technical staff and executive leadership. The report must communicate the risk of a publicly accessible storage bucket that was found. Which approach is most effective for the report?
Select an answer first - 20
What is the goal of cloud service enumeration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.