The SecOps Group CCPenX-Az Certified Cloud Pentesting eXpert - Azure Exam Practice Test
Certified Cloud Pentesting eXpert - Azure Questions and Answers
From inside the App Service environment, request an Azure Resource Manager token using the managed identity endpoint. Which resource value should be requested for Azure Resource Manager access?
Using the managed identity principal ID discovered in the previous task, identify which Azure RBAC role is assigned to it.
Using the previously retrieved credentials, authenticate as the App Registration within the tenant and enumerate potential lateral movement vectors. Which of the following roles is assigned to the App Registration?
During network reconnaissance of an Azure VM, you inspect its Network Security Group. Which inbound rule creates the highest risk?
Using the previously gained access to the Azure environment, extract an access token from the Web App’s environment and use it to impersonate its Managed Identity. Which of the following roles is assigned to the Web App’s Security Principal?
A storage account allows public blob access. Enumerate containers and identify the public container that exposes backup files.
A managed identity has Key Vault Secrets User access to kv-finance-prod. Enumerate secrets and retrieve the hidden flag.
A compromised principal has permission to list role assignments. Identify which user has the User Access Administrator role at the resource group scope.
You are reviewing Azure Activity Logs after a lab compromise. Which operation indicates that an attacker reset another user’s password through Microsoft Entra ID?