Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: big75certs

Free and Premium The SecOps Group CCPenX-Az Dumps Questions Answers

Page: 1 / 2
Total 31 questions

Certified Cloud Pentesting eXpert - Azure Questions and Answers

Question 1

During App Service enumeration, you discover that the compromised user can read App Service application settings. Find the hidden flag stored in the application settings.

Options:

Buy Now
Question 2

Inside the public blob container, a file named backup-config.json contains service principal credentials. What field contains the App Registration client ID?

Options:

A.

tenantId

B.

clientSecret

C.

clientId

D.

objectId

Question 3

ExcaliburCorp has recently migrated part of its infrastructure to Microsoft Azure. Shortly after the migration, the company suffered a security breach resulting in the exposure of sensitive internal data. Their investigation revealed that the attack originated from a disgruntled developer who has since disappeared. To assess and mitigate further risks, ExcaliburCorp has granted you access to a replica Azure environment with the same permissions the developer had at the time of the incident. Your task is to simulate the attacker’s actions, uncover the full extent of the compromise, and identify vulnerable configurations or services that enabled the breach.

Using the provided Azure login credentials, perform OSINT and reconnaissance to identify the Azure Active Directory/AAD Tenant ID associated with the environment.

Options:

Question 4

A managed identity has Key Vault Secrets User access to kv-finance-prod. Enumerate secrets and retrieve the hidden flag.

Options:

Question 5

You are reviewing Azure Activity Logs after a lab compromise. Which operation indicates that an attacker reset another user’s password through Microsoft Entra ID?

Options:

A.

Microsoft.Authorization/roleAssignments/write

B.

Update user / password profile modification

C.

Microsoft.Storage/storageAccounts/listKeys/action

D.

Microsoft.KeyVault/vaults/secrets/read

Question 6

During network reconnaissance of an Azure VM, you inspect its Network Security Group. Which inbound rule creates the highest risk?

Options:

A.

Allow TCP 443 from Internet

B.

Allow TCP 22 from Internet

C.

Deny all inbound from Internet

D.

Allow TCP 1433 from private subnet only

Question 7

A storage account allows public blob access. Enumerate containers and identify the public container that exposes backup files.

Options:

Question 8

You find a SAS token in a table entity. The token starts with:

?sv=2025-01-05 & ss=b & srt=sco & sp=rl & se=2026-08-01T00:00:00Z

Which permissions does sp=rl grant?

Options:

A.

Read and List

B.

Read and Write

C.

Write and Delete

D.

List and Delete

Question 9

Using the privileges of the previously compromised App Registration, explore the Azure environment to identify and access sensitive information. What is the final flag retrieved from the tenant?

Options:

Exam Detail
Exam Code: CCPenX-Az
Last Update: Sep 29, 2026
CCPenX-Az Question Answers
Page: 1 / 2
Total 31 questions