Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > The SecOps Group > Cloud Pentesting eXpert > CCPenX-Az

CCPenX-Az Certified Cloud Pentesting eXpert - Azure Question and Answers

Question # 4

Using the managed identity principal ID discovered in the previous task, identify which Azure RBAC role is assigned to it.

A.

Reader

B.

Storage Blob Data Reader

C.

Key Vault Secrets User

D.

Contributor

Full Access
Question # 5

You find a SAS token in a table entity. The token starts with:

?sv=2025-01-05 & ss=b & srt=sco & sp=rl & se=2026-08-01T00:00:00Z

Which permissions does sp=rl grant?

A.

Read and List

B.

Read and Write

C.

Write and Delete

D.

List and Delete

Full Access
Question # 6

During network reconnaissance of an Azure VM, you inspect its Network Security Group. Which inbound rule creates the highest risk?

A.

Allow TCP 443 from Internet

B.

Allow TCP 22 from Internet

C.

Deny all inbound from Internet

D.

Allow TCP 1433 from private subnet only

Full Access
Question # 7

During App Service enumeration, you discover that the compromised user can read App Service application settings. Find the hidden flag stored in the application settings.

Full Access
Question # 8

After gaining access to the Azure tenant, enumerate all resource groups available to the compromised user. One resource group contains the word prod. What is the name of that resource group?

Full Access
Question # 9

Carefully enumerate the accessible Azure Blob Container to locate a file containing credentials for an App Registration within the tenant. What is the Application/Client ID of the discovered App Registration?

Full Access