Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 118 Topic 12 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 118 Topic 12 Discussion

312-50v13 Exam Topic 12 Question 118 Discussion:
Question #: 118
Topic #: 12

A multinational healthcare provider headquartered in Boston, Massachusetts relies on federated authentication to allow employees to access multiple cloud-hosted applications using a single sign-on portal. During an authorized red team engagement, a security consultant gains access to the organization ' s identity infrastructure and extracts signing material used in trust relationships between the internal identity provider and external cloud services. Using this material, the consultant generates authentication responses that grant administrative-level access to several cloud applications without interacting with user credentials or triggering multifactor authentication challenges. The access appears legitimate within the cloud service logs. Which cloud attack technique best aligns with this behavior?


A.

Golden SAML Attack


B.

Man-in-the-Cloud (MITC) Attack


C.

Cloud Hopper Attack


D.

Living off the Cloud (LotC) Attack


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.