nerdexam
CompTIA

PT0-002 · Question #550

A penetration tester is assessing the security of a client's externally facing cloud infrastructure. After running reconnaissance, the tester notices that several services and systems are exposed…

The correct answer is D. Object storage misconfiguration. The scenario describes confidential documents being available without any security controls. In cloud environments, such documents are typically stored in object storage services (e.g., AWS S3 buckets, Azure Blob Storage, or Google Cloud Storage). A common misconfiguration…

Vulnerability discovery and analysis

Question

A penetration tester is assessing the security of a client's externally facing cloud infrastructure. After running reconnaissance, the tester notices that several services and systems are exposed, including a web server, application server, storage buckets, and an unknown portal requiring authentication. After closely examining each of the exposed resources, the tester stumbles upon confidential documents available without any security controls. Which of the following is the most likely reason the resources are exposed?

Options

  • AIAM misconfiguration
  • BFederation misconfiguration
  • CAccess token misconfiguration
  • DObject storage misconfiguration

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    4% (1)
  • D
    78% (18)

Explanation

The scenario describes confidential documents being available without any security controls. In cloud environments, such documents are typically stored in object storage services (e.g., AWS S3 buckets, Azure Blob Storage, or Google Cloud Storage). A common misconfiguration occurs when these storage buckets are set to be publicly accessible, either intentionally or accidentally, exposing sensitive files to unauthorized access.

Topics

#Cloud Security Misconfiguration#Object Storage Security#Data Exposure

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice