nerdexam
CompTIA

PT0-002 · Question #561

A penetration tester is testing a client's infrastructure and discovers an API that provides information about the infrastructure that can be used to configure or manage the instances. The…

The correct answer is D. Metadata service. In cloud environments, APIs often expose metadata services that provide information about the instances and configuration details. These metadata services can be accessed from within the The penetration tester exploited the metadata service to obtain temporary credentials for…

Attacks and Exploits

Question

A penetration tester is testing a client's infrastructure and discovers an API that provides information about the infrastructure that can be used to configure or manage the instances. The penetration tester uses this API to obtain temporary credentials used to access the infrastructure. Which of the following types of attacks did the penetration tester use?

Options

  • ADirect-to-origin
  • BSide-channel
  • CCloud malware injection
  • DMetadata service

How the community answered

(33 responses)
  • A
    12% (4)
  • B
    3% (1)
  • C
    6% (2)
  • D
    79% (26)

Explanation

In cloud environments, APIs often expose metadata services that provide information about the instances and configuration details. These metadata services can be accessed from within the The penetration tester exploited the metadata service to obtain temporary credentials for accessing the infrastructure. This type of attack is known as a Metadata Service Exploitation and is commonly associated with improper configurations or insufficient access restrictions in cloud Once the credentials are obtained, they can be used to perform further actions, such as accessing other cloud services or resources.

Topics

#Cloud Security#API Security#Instance Metadata Service#Credential Theft

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice