Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Penetration Tester

Domain 1Objective 2

Red Team Penetration Testing of Cloud Environments GCPN Practice Questions (Page 5)

Part of the Cloud Penetration Testing Fundamentals domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
11concepts

Questions 21–25

  1. 21application · medium

    A red teamer has obtained a set of valid AWS access keys for a low-privileged IAM user. The engagement scope allows testing privilege escalation. Which technique is most appropriate to attempt first?

    Select an answer first
  2. 22application · medium

    During the planning phase of a cloud red team engagement, the team is identifying high-value targets. The client's environment includes a public-facing web application, a customer database in a managed database service, and a CI/CD pipeline with secrets stored in a cloud secrets manager. The team wants to prioritize targets that could lead to broad compromise. Which target should be considered the highest priority?

    Select an answer first
  3. 23application · medium

    A red team engagement is being planned against a multi-cloud environment (AWS and Azure). The client has approved testing of production workloads but explicitly excluded any activity that could disrupt the payment processing service. During the reconnaissance phase, the team identifies a public S3 bucket that appears to contain configuration files. Which action best aligns with the engagement scope and rules of engagement?

    Select an answer first
  4. 24foundation · easy

    Why is it important to understand cloud logging capabilities during a red team engagement?

    Select an answer first
  5. 25application · medium

    After compromising an AWS account, you want to establish persistence that survives a password reset and is less likely to be detected. Which method is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.