Courseiva

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

Which TWO of the following are cloud-specific security threats?

⚠ Common exam trap

EC-Council often tests the distinction between general web/network attacks and those that exploit cloud-specific features like metadata services or object storage permissions, leading candidates to mistakenly classify SQL injection or ARP spoofing as cloud threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

S3 bucket misconfiguration

Option D (S3 bucket misconfiguration) is a cloud-specific threat because it exploits the shared responsibility model in AWS, where an improperly configured bucket ACL or bucket policy can expose object storage publicly over the internet, a risk unique to cloud object storage services. Option E (SSRF in cloud) is cloud-specific because server-side request forgery can be used to reach the cloud instance metadata service (e.g., 169.254.169.254) and steal temporary IAM credentials from instance roles, an attack path that only exists in cloud environments. The unmarked options do not belong: SQL injection (A) is a generic web application vulnerability targeting database query construction, de-authentication attack (B) is a Wi-Fi layer 2 denial-of-service technique against 802.11 management frames, and ARP spoofing (C) is a LAN-based man-in-the-middle attack on IPv4-to-MAC resolution, none of which are specific to cloud platforms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection is a classic web application vulnerability that exploits improper input validation, allowing attackers to manipulate backend database queries. This attack vector targets the application layer and its interaction with a database, regardless of whether the application is hosted on-premises, in a virtual machine, or within a serverless function in the cloud. While cloud environments may host applications susceptible to SQL injection, the vulnerability itself is not inherent to cloud infrastructure or services, making it a general application security concern rather than cloud-specific.

  • ✗

    De-authentication attack

    Why it's wrong here

    A de-authentication attack is a denial-of-service technique specifically targeting wireless networks, where an attacker sends forged de-authentication frames to disconnect legitimate clients from an access point. This attack operates at the MAC layer (Layer 2) of the OSI model and relies on physical proximity to the wireless network infrastructure. Cloud environments, by their nature, abstract away the underlying physical network layer from the end-user or application, meaning such an attack cannot directly target cloud services or infrastructure.

  • ✗

    ARP spoofing

    Why it's wrong here

    ARP spoofing, or ARP poisoning, is a network-level attack where an attacker sends forged Address Resolution Protocol (ARP) messages over a local area network. This tricks devices into associating the attacker's MAC address with the IP address of another legitimate host, enabling man-in-the-middle attacks. This vulnerability is specific to broadcast domains and local network segments. While cloud providers use virtual networks, the underlying infrastructure typically prevents direct ARP manipulation by tenants, making it not a cloud-specific threat that a tenant would directly face or exploit against cloud services.

  • ✓

    S3 bucket misconfiguration

    Why this is correct

    S3 bucket misconfiguration refers to incorrectly set permissions or access control lists (ACLs) on Amazon S3 storage buckets, leading to unintended public exposure or unauthorized access to sensitive data. This is a prevalent cloud-specific threat because S3 is a fundamental cloud storage service, and its complex permission models, combined with user error or lack of understanding, frequently result in data breaches. The ease of creating and deploying S3 buckets, coupled with the potential for global access, makes misconfiguration a unique and critical cloud security challenge.

  • ✓

    SSRF in cloud

    Why this is correct

    Server-Side Request Forgery (SSRF) in cloud environments is a critical vulnerability where an attacker can induce a server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing. In cloud contexts, this is particularly dangerous because it can be exploited to access internal cloud metadata services (e.g., AWS EC2 Instance Metadata Service, Azure Instance Metadata Service). These services often contain sensitive information like temporary credentials, instance roles, and network configurations, which, if compromised via SSRF, can lead to significant privilege escalation and lateral movement within the cloud infrastructure.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.