โ† All Certified Ethical Hacker Flashcard Decks

Cloud Security and Penetration Testing Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Security and Penetration Testing flashcards as text
  1. What is 'cloud hopping' in the context of CEH?

    Answer: Using one compromised cloud account to attack another

    Cloud hopping is an attack where a threat actor compromises one cloud account or tenant and uses it as a pivot point to attack other cloud accounts.

  2. Which AWS service, if misconfigured, can expose all stored objects to the public internet?

    Answer: S3 Bucket ACLs

    Misconfigured S3 bucket ACLs or bucket policies can make all stored objects publicly readable, leading to data exposure.

  3. During cloud pen testing, what does 'privilege escalation via IAM misconfiguration' typically involve?

    Answer: Attaching higher-privilege policies to a compromised IAM entity

    IAM privilege escalation involves using permissions like iam:AttachUserPolicy or iam:PassRole to grant a compromised identity elevated cloud privileges.

  4. What is the purpose of AWS CloudTrail in a security context?

    Answer: Logging API calls and user activity for auditing

    AWS CloudTrail records API calls and management events across an AWS account, providing an audit trail for security analysis and compliance.

  5. Which type of cloud attack involves injecting malicious content into a cloud service to be executed by other users or services?

    Answer: Cross-Cloud Scripting (XCS)

    Cross-Cloud Scripting (XCS) is similar to XSS but targets cloud-hosted applications, injecting malicious scripts that execute in the context of other cloud users.

  6. What is 'hyperjacking' in cloud security?

    Answer: Installing a rogue hypervisor to control virtual machines

    Hyperjacking involves replacing or compromising a legitimate hypervisor with a malicious one, giving the attacker covert control over all VMs on that host.