Cloud Security and Penetration Testing Flashcards
6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Security and Penetration Testing flashcards as text
Which attack targets the cloud management plane to gain administrative control over an entire cloud environment?
Answer: Wrapping Attack
A wrapping attack (XML Signature Wrapping) manipulates SOAP messages to the cloud management API, potentially granting attacker admin access.
What is the primary purpose of a Cloud Access Security Broker (CASB)?
Answer: To enforce security policies between cloud users and providers
A CASB acts as an intermediary between cloud users and providers to enforce security policies such as DLP, access control, and threat protection.
During a cloud penetration test, an attacker discovers an EC2 instance metadata endpoint at 169.254.169.254. What is the risk?
Answer: Exposure of IAM credentials via SSRF
The EC2 instance metadata endpoint can expose temporary IAM role credentials when accessed via SSRF, allowing privilege escalation in AWS.
Which tool is commonly used to test for misconfigured AWS S3 bucket permissions?
Answer: S3Scanner
S3Scanner enumerates and checks the permissions of Amazon S3 buckets to identify publicly accessible or misconfigured buckets.
What does the shared responsibility model in cloud security define?
Answer: Which security tasks belong to the provider versus the customer
The shared responsibility model delineates which security controls are managed by the cloud provider and which are the customer's responsibility.
Which container escape technique exploits a misconfigured Docker socket mounted inside a container?
Answer: Docker socket abuse
Mounting the Docker socket (/var/run/docker.sock) inside a container allows an attacker to control the host Docker daemon and escape the container.