โ† All Certified Ethical Hacker Flashcard Decks

Cloud Security and Penetration Testing Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Security and Penetration Testing flashcards as text
  1. Which cloud service model gives the customer the most control over the underlying infrastructure?

    Answer: IaaS

    IaaS (Infrastructure as a Service) gives customers the greatest control, including over operating systems, storage, and networking.

  2. What is the term for a cloud attack where an attacker exploits shared physical hardware to access another tenant's data?

    Answer: Side-Channel Attack

    A side-channel attack exploits information gained from the physical implementation of shared hardware to extract data from co-located tenants.

  3. Which CEH-recognized tool is commonly used for cloud infrastructure enumeration and S3 bucket discovery?

    Answer: ScoutSuite

    ScoutSuite is a multi-cloud security auditing tool used to enumerate cloud resources and identify misconfigurations including exposed S3 buckets.

  4. What type of cloud deployment model is used exclusively by a single organization and hosted either on-premises or by a third party?

    Answer: Private Cloud

    A private cloud is dedicated to a single organization and offers greater control and security than public cloud deployments.

  5. An attacker uses stolen OAuth tokens to access cloud resources without knowing the user's password. What type of attack is this?

    Answer: Man-in-the-Cloud Attack

    A man-in-the-cloud attack intercepts or steals OAuth tokens stored on endpoints to access cloud services without credentials.

  6. Which security concept ensures that cloud provider employees cannot access customer data without authorization?

    Answer: Separation of Duties

    Separation of duties prevents any single individual, including cloud provider employees, from having unrestricted access to customer data.