Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

The SecOps Group CCPenX-Az - Certified Cloud Pentesting eXpert - Azure

Page: 1 / 1
Total 31 questions

Using the previously retrieved credentials, authenticate as the App Registration within the tenant and enumerate potential lateral movement vectors. Which of the following roles is assigned to the App Registration?

A.

Key Vault Secrets User

B.

Cosmos DB Built-in Data Reader

C.

Container Apps Reader Role

D.

None of the above

Using the Azure access of the second compromised user, perform lateral movement within the environment to discover sensitive information. What is the flag uncovered during this activity?

You’ve discovered that the compromised user holds directory-level privileges. Enumerate how this role can be abused to compromise another user in the directory. What is the Job Title attribute of the compromised target user?

A storage account allows public blob access. Enumerate containers and identify the public container that exposes backup files.

A managed identity has Key Vault Secrets User access to kv-finance-prod. Enumerate secrets and retrieve the hidden flag.

After authenticating as the service principal, enumerate its assigned Azure RBAC role. Which role does it have?

A.

Reader

B.

Contributor

C.

Storage Account Contributor

D.

Owner

Authenticate to Azure as a service principal using the credentials found in backup-config.json.

Using the previously gained access to the Azure environment, extract an access token from the Web App’s environment and use it to impersonate its Managed Identity. Which of the following roles is assigned to the Web App’s Security Principal?

A.

Compute-Instance-Inspector

B.

VM-Metadata-Reader

C.

Storage-Metadata-Reader

D.

AppService-Auditor

You are reviewing Azure Activity Logs after a lab compromise. Which operation indicates that an attacker reset another user’s password through Microsoft Entra ID?

A.

Microsoft.Authorization/roleAssignments/write

B.

Update user / password profile modification

C.

Microsoft.Storage/storageAccounts/listKeys/action

D.

Microsoft.KeyVault/vaults/secrets/read