During a web application test, a tester discovers an endpoint that fetches a URL from user input without validation. They attempt to access the AWS metadata endpoint. Which IP address is commonly used for the cloud metadata service?
169.254.169.254 is the link-local address used by AWS, Azure and GCP instance metadata services. Reaching it via an unvalidated URL-fetch parameter demonstrates server-side request forgery, letting the tester retrieve IAM credentials and instance configuration from the cloud metadata endpoint.
Why this answer
169.254.169.254 is the link-local IPv4 address used by AWS EC2 Instance Metadata Service (IMDS), and it is also used by Azure, GCP, and OpenStack for their metadata services. An SSRF vulnerability that can reach this address can retrieve IAM credentials from the instance role, making it a critical finding in cloud-hosted web app tests.
Exam trap
The trap is confusing the metadata IP with common private or loopback addresses — candidates who have not memorized 169.254.169.254 may pick 127.0.0.1 thinking 'local service,' but the metadata service is a distinct link-local endpoint.
How to eliminate wrong answers
Option B is wrong because 10.0.0.1 is a private RFC 1918 address commonly used as a VPC gateway or router, not the metadata service. Option C is wrong because 127.0.0.1 is the IPv4 loopback address — it refers to the local host, not the cloud metadata endpoint. Option D is wrong because 192.168.1.1 is a typical home/office router LAN address, unrelated to cloud metadata.