Pre-Winter Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

The SecOps Group CCPenX-Az Dumps

Page: 1 / 3
Total 31 questions

Certified Cloud Pentesting eXpert - Azure Questions and Answers

Question 1

Carefully enumerate the accessible Azure Blob Container to locate a file containing credentials for an App Registration within the tenant. What is the Application/Client ID of the discovered App Registration?

Options:

Question 2

You find a SAS token in a table entity. The token starts with:

?sv=2025-01-05 & ss=b & srt=sco & sp=rl & se=2026-08-01T00:00:00Z

Which permissions does sp=rl grant?

Options:

A.

Read and List

B.

Read and Write

C.

Write and Delete

D.

List and Delete

Question 3

A compromised developer account has Reader access to a resource group. Enumerate all Azure resources in that resource group and identify the exposed App Service name.

Options:

Question 4

ExcaliburCorp has recently migrated part of its infrastructure to Microsoft Azure. Shortly after the migration, the company suffered a security breach resulting in the exposure of sensitive internal data. Their investigation revealed that the attack originated from a disgruntled developer who has since disappeared. To assess and mitigate further risks, ExcaliburCorp has granted you access to a replica Azure environment with the same permissions the developer had at the time of the incident. Your task is to simulate the attacker’s actions, uncover the full extent of the compromise, and identify vulnerable configurations or services that enabled the breach.

Using the provided Azure login credentials, perform OSINT and reconnaissance to identify the Azure Active Directory/AAD Tenant ID associated with the environment.

Options:

Question 5

During App Service enumeration, you discover that the compromised user can read App Service application settings. Find the hidden flag stored in the application settings.

Options:

Question 6

After gaining access to the Azure tenant, enumerate all resource groups available to the compromised user. One resource group contains the word prod. What is the name of that resource group?

Options:

Question 7

The compromised service principal has Contributor access to a resource group but no direct Key Vault data-plane role. Can it immediately read Key Vault secret values?

Options:

A.

Yes, Contributor includes secret read permissions

B.

No, Contributor does not automatically grant Key Vault secret data-plane read

C.

Yes, if the vault is in the same resource group

D.

No, service principals cannot access Key Vault

Question 8

A storage account allows public blob access. Enumerate containers and identify the public container that exposes backup files.

Options:

Question 9

Using a discovered SAS token with read/list permissions, enumerate blobs inside the sensitive-exports container. Which file contains credentials?

Options:

Page: 1 / 3
Total 31 questions