nerdexam
CompTIA

PT0-002 · Question #344

During the assessment of a client's cloud and on-premises environments, a penetration tester was able to gain ownership of a storage object within the cloud environment using the provided…

The correct answer is A. Federation misconfiguration of the container. Another major way into cloud environments is through exploitation of misconfigured services. Although improperly set up or overly permissive identity and access management (IAM) is one of the most commonly leveraged weaknesses, federation configuration issues, insecure object…

Attacks and Exploits

Question

During the assessment of a client's cloud and on-premises environments, a penetration tester was able to gain ownership of a storage object within the cloud environment using the provided on-premises credentials. Which of the following BEST describes why the tester was able to gain access?

Options

  • AFederation misconfiguration of the container
  • BKey mismanagement between the environments
  • CIaaS failure at the provider
  • DContainer listed in the public domain

How the community answered

(55 responses)
  • A
    75% (41)
  • B
    5% (3)
  • C
    16% (9)
  • D
    4% (2)

Explanation

Another major way into cloud environments is through exploitation of misconfigured services. Although improperly set up or overly permissive identity and access management (IAM) is one of the most commonly leveraged weaknesses, federation configuration issues, insecure object storage in services like S3, or weak configuration in containerization services can all allow you to gain a foothold in a cloud environment.

Topics

#Federation misconfiguration#Identity and Access Management (IAM)#Cloud security#Privilege escalation

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice