Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Certified Cloud Pentesting eXpert - Azure

Last Update 7 hours ago Total Questions : 31

The Certified Cloud Pentesting eXpert - Azure content is now fully updated, with all current exam questions added 7 hours ago. Deciding to include CCPenX-Az practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CCPenX-Az exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CCPenX-Az sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Certified Cloud Pentesting eXpert - Azure practice test comfortably within the allotted time.

Question # 1

A compromised developer account has Reader access to a resource group. Enumerate all Azure resources in that resource group and identify the exposed App Service name.

Question # 2

During network reconnaissance of an Azure VM, you inspect its Network Security Group. Which inbound rule creates the highest risk?

A.

Allow TCP 443 from Internet

B.

Allow TCP 22 from Internet

C.

Deny all inbound from Internet

D.

Allow TCP 1433 from private subnet only

Question # 3

Inside the public blob container, a file named backup-config.json contains service principal credentials. What field contains the App Registration client ID?

A.

tenantId

B.

clientSecret

C.

clientId

D.

objectId

Question # 4

During App Service enumeration, you discover that the compromised user can read App Service application settings. Find the hidden flag stored in the application settings.

Question # 5

Using the Azure access of the second compromised user, perform lateral movement within the environment to discover sensitive information. What is the flag uncovered during this activity?

Question # 6

A managed identity has Key Vault Secrets User access to kv-finance-prod. Enumerate secrets and retrieve the hidden flag.

Question # 7

Authenticate to Azure as a service principal using the credentials found in backup-config.json.

Question # 8

The compromised service principal has Contributor access to a resource group but no direct Key Vault data-plane role. Can it immediately read Key Vault secret values?

A.

Yes, Contributor includes secret read permissions

B.

No, Contributor does not automatically grant Key Vault secret data-plane read

C.

Yes, if the vault is in the same resource group

D.

No, service principals cannot access Key Vault

Question # 9

You discover a storage account named prodreportstore01. Determine whether public blob access is enabled on the storage account.