Weekend Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: CFsave75

Pass the The SecOps Group Cloud Pentesting eXpert CCPenX-Az Questions and answers with CertsForce

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

A compromised developer account has Reader access to a resource group. Enumerate all Azure resources in that resource group and identify the exposed App Service name.


Expert Solution
Questions # 2:

You’ve discovered that the compromised user holds directory-level privileges. Enumerate how this role can be abused to compromise another user in the directory. What is the Job Title attribute of the compromised target user?


Expert Solution
Questions # 3:

A virtual machine has a system-assigned managed identity. From the VM shell, which Azure CLI command authenticates using that identity?

Options:

A.

az login --service-principal


B.

az login --identity


C.

az account get-access-token --tenant


D.

az ad signed-in-user show


Expert Solution
Questions # 4:

Authenticate to Azure as a service principal using the credentials found in backup-config.json.


Expert Solution
Questions # 5:

During App Service enumeration, you discover that the compromised user can read App Service application settings. Find the hidden flag stored in the application settings.


Expert Solution
Questions # 6:

You have been given a breached Azure user credential for an authorized lab tenant:

james.ward@cloudcorpsec.onmicrosoft.com

After logging in, identify the Azure Tenant ID and Subscription ID associated with the account.


Expert Solution
Questions # 7:

Using the privileges of the previously compromised App Registration, explore the Azure environment to identify and access sensitive information. What is the final flag retrieved from the tenant?


Expert Solution
Questions # 8:

With access to the Web App’s Managed Identity, you can now query certain Azure Resources. Use this access to uncover the hidden secret left behind during provisioning. What is the secret?


Expert Solution
Questions # 9:

Inside the public blob container, a file named backup-config.json contains service principal credentials. What field contains the App Registration client ID?

Options:

A.

tenantId


B.

clientSecret


C.

clientId


D.

objectId


Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions