Courseiva

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

Which THREE of the following are valid methods for exploiting cloud misconfigurations? (Select 3)

⚠ Common exam trap

CEH often tests the distinction between cloud-specific misconfigurations and generic application or network attacks, so candidates must recognize that SQL injection and DDoS are not cloud misconfiguration exploits.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a container escape to access the host OS

Option A is correct because a container escape exploits a misconfigured or vulnerable container runtime (e.g., privileged containers, exposed Docker socket, or kernel flaws) to break isolation and reach the underlying host OS, a classic cloud misconfiguration risk. Option B is correct because an S3 bucket configured with public read access is a well-known cloud storage misconfiguration that lets anyone list and download objects, exposing sensitive files. Option E is correct because overly permissive IAM roles (e.g., wildcard actions like iam:* or sts:AssumeRole on broad resources) are a cloud identity misconfiguration that attackers abuse to escalate privileges. Option C is not specific to cloud misconfigurations—SQL injection is an application-layer vulnerability independent of cloud configuration. Option D is also not a cloud misconfiguration exploit; a DDoS attack from a botnet abuses network/volumetric resources rather than a misconfigured cloud setting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using a container escape to access the host OS

    Why this is correct

    Using a container escape to access the host OS is a critical cloud misconfiguration vulnerability. This occurs when a flaw in the container runtime, kernel, or container configuration allows an attacker to break out of the isolated container environment and gain unauthorized access to the underlying host operating system. Such an escape often leverages misconfigured capabilities, insecure mounts, or unpatched kernel vulnerabilities, directly exposing the host infrastructure to compromise.

  • ✓

    Exploiting an S3 bucket with public read access to download sensitive files

    Why this is correct

    Exploiting an S3 bucket with public read access to download sensitive files represents a common cloud misconfiguration. When an Amazon S3 bucket's access control policies are incorrectly configured to allow public read permissions, any internet user can access and download its contents without authentication. This oversight frequently leads to data breaches involving proprietary information, customer data, or internal credentials, making it a direct result of a security misconfiguration.

  • ✗

    Performing a SQL injection on a web application

    Why it's wrong here

    Performing a SQL injection on a web application is a classic application-layer vulnerability, not a cloud misconfiguration. While the web application might be hosted in the cloud, SQL injection exploits flaws in the application's code that improperly handle user input, allowing malicious SQL queries to be executed against its database. This attack targets the software logic itself, rather than misconfigured cloud infrastructure services or permissions.

  • ✗

    Launching a DDoS attack from a botnet

    Why it's wrong here

    Launching a DDoS attack from a botnet describes an attack method or threat, rather than a cloud misconfiguration that enables exploitation. A Distributed Denial of Service (DDoS) attack aims to overwhelm a target system with traffic, rendering it unavailable, and is typically executed using a network of compromised machines (a botnet). While cloud resources can be targets or sources of DDoS attacks, the attack itself is not a misconfiguration within the cloud environment.

  • ✓

    Abusing overly permissive IAM roles to escalate privileges

    Why this is correct

    Abusing overly permissive IAM roles to escalate privileges is a prime example of exploiting a cloud misconfiguration. Identity and Access Management (IAM) roles, when configured with excessive permissions, grant entities more access than necessary to perform their intended functions. An attacker who compromises an entity with such a role can leverage these broad permissions to escalate their privileges, gain control over additional resources, or access sensitive data within the cloud environment.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are cloud-specific security threats?

easy
  • A.SQL injection
  • B.De-authentication attack
  • C.ARP spoofing
  • ✓ D.S3 bucket misconfiguration
  • ✓ E.SSRF in cloud

Why D: Option D (S3 bucket misconfiguration) is a cloud-specific threat because it exploits the shared responsibility model in AWS, where an improperly configured bucket ACL or bucket policy can expose object storage publicly over the internet, a risk unique to cloud object storage services. Option E (SSRF in cloud) is cloud-specific because server-side request forgery can be used to reach the cloud instance metadata service (e.g., 169.254.169.254) and steal temporary IAM credentials from instance roles, an attack path that only exists in cloud environments. The unmarked options do not belong: SQL injection (A) is a generic web application vulnerability targeting database query construction, de-authentication attack (B) is a Wi-Fi layer 2 denial-of-service technique against 802.11 management frames, and ARP spoofing (C) is a LAN-based man-in-the-middle attack on IPv4-to-MAC resolution, none of which are specific to cloud platforms.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.