Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

The SecOps Group CCPenX-Az Certified Cloud Pentesting eXpert - Azure Exam Practice Test

Page: 1 / 3
Total 31 questions

Certified Cloud Pentesting eXpert - Azure Questions and Answers

Question 1

From inside the App Service environment, request an Azure Resource Manager token using the managed identity endpoint. Which resource value should be requested for Azure Resource Manager access?

Options:

A.

https://graph.microsoft.com/

B.

https://management.azure.com/

C.

https://vault.azure.net/

D.

https://storage.azure.com/

Question 2

Using the managed identity principal ID discovered in the previous task, identify which Azure RBAC role is assigned to it.

Options:

A.

Reader

B.

Storage Blob Data Reader

C.

Key Vault Secrets User

D.

Contributor

Question 3

Using the previously retrieved credentials, authenticate as the App Registration within the tenant and enumerate potential lateral movement vectors. Which of the following roles is assigned to the App Registration?

Options:

A.

Key Vault Secrets User

B.

Cosmos DB Built-in Data Reader

C.

Container Apps Reader Role

D.

None of the above

Question 4

During network reconnaissance of an Azure VM, you inspect its Network Security Group. Which inbound rule creates the highest risk?

Options:

A.

Allow TCP 443 from Internet

B.

Allow TCP 22 from Internet

C.

Deny all inbound from Internet

D.

Allow TCP 1433 from private subnet only

Question 5

Using the previously gained access to the Azure environment, extract an access token from the Web App’s environment and use it to impersonate its Managed Identity. Which of the following roles is assigned to the Web App’s Security Principal?

Options:

A.

Compute-Instance-Inspector

B.

VM-Metadata-Reader

C.

Storage-Metadata-Reader

D.

AppService-Auditor

Question 6

A storage account allows public blob access. Enumerate containers and identify the public container that exposes backup files.

Options:

Question 7

A managed identity has Key Vault Secrets User access to kv-finance-prod. Enumerate secrets and retrieve the hidden flag.

Options:

Question 8

A compromised principal has permission to list role assignments. Identify which user has the User Access Administrator role at the resource group scope.

Options:

Question 9

You are reviewing Azure Activity Logs after a lab compromise. Which operation indicates that an attacker reset another user’s password through Microsoft Entra ID?

Options:

A.

Microsoft.Authorization/roleAssignments/write

B.

Update user / password profile modification

C.

Microsoft.Storage/storageAccounts/listKeys/action

D.

Microsoft.KeyVault/vaults/secrets/read

Page: 1 / 3
Total 31 questions