20+ practice questions focused on Cloud And Hybrid Infrastructure Security — one of the most tested topics on the EC-Council Certified Penetration Testing Professional (CPENT) (CPENT) exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Cloud And Hybrid Infrastructure Security PracticeA penetration tester is analyzing a Kubernetes cluster deployed on AWS (EKS) where a compromised pod is running with a service account that has access to the AWS IAM OIDC provider endpoint. The pod's container is running as root and has the host network namespace enabled. Which technique allows the tester to pivot from the container to the underlying cloud infrastructure?
Explanation: Accessing the container metadata or using the token exchange via the IAM OIDC provider allows the tester to obtain cloud credentials.
While reviewing a hybrid identity deployment utilizing Azure AD Connect, a penetration tester observes that Password Hash Sync (PHS) is enabled alongside Pass-Through Authentication (PTA). What security implication does this configuration present during an on-premises domain compromise?
Explanation: When PHS is enabled, synchronized password hashes reside in Azure AD, meaning a complete on-premises compromise exposes the hashes of all synced accounts to cloud credential dumping if Azure AD is later targeted.
An auditor finds an Amazon S3 bucket configured with public read access enabled via an Access Control List (ACL), but the bucket policy explicitly denies public read access. How does AWS evaluate these conflicting permissions?
Explanation: AWS evaluation logic states that an explicit Deny anywhere in the policy evaluation overrides all allows.
A penetration tester gains shell access inside a Docker container running on a Linux host. They inspect the container's capabilities using capsh --print and notice CAP_SYS_ADMIN is enabled, and the cgroup v1 filesystem is mounted read-write inside the container. Which specific container escape vector is immediately available?
Explanation: Writing a malicious payload to the release_agent file in cgroups combined with triggering a notification via the notify_on_release mechanism allows executing commands on the host as root.
During an Azure assessment, an auditor finds that a Logic App has an HTTP trigger with no authentication mechanism configured (Anonymous access). The Logic App has permissions to read sensitive Azure Blob Storage containers. What type of vulnerability does this represent?
Explanation: Unauthenticated HTTP triggers in Azure Logic Apps allow external unauthenticated actors to invoke workflows, leading to unauthorized data access.
+15 more Cloud And Hybrid Infrastructure Security questions available
Practice all Cloud And Hybrid Infrastructure Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Cloud And Hybrid Infrastructure Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Cloud And Hybrid Infrastructure Security questions on the CPENT frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Cloud And Hybrid Infrastructure Security is tested as part of the EC-Council Certified Penetration Testing Professional (CPENT) (CPENT) blueprint. Practicing with targeted Cloud And Hybrid Infrastructure Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CPENT practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Cloud And Hybrid Infrastructure Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Cloud And Hybrid Infrastructure Security practice session with instant scoring and detailed explanations.
Start Cloud And Hybrid Infrastructure Security Practice →