Courseiva
Cloud And Hybrid Infrastructure SecuritymediumMultiple ChoiceObjective-mapped

CPENT Cloud And Hybrid Infrastructure Security Practice Question

An attacker gains access to an Azure environment and enumerates App Service Configuration settings. They discover that connection strings and database passwords are stored in plaintext within the application settings rather than being referenced via Azure Key Vault references. What attack path does this enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Any user or service principal with read access to the App Service configuration can extract plaintext database credentials.

Storing secrets in plaintext in App Service configuration settings allows any user or service principal with Reader or Contributor access to the App Service to harvest sensitive credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The attacker can perform a Golden Ticket attack against the Azure Active Directory Domain Services.

    Why it's wrong here

    Golden tickets require Krbtgt hash access, unrelated to App Service settings.

  • Azure Firewall automatically terminates the web application due to compliance violations.

    Why it's wrong here

    Azure Firewall does not parse application configuration files.

  • Any user or service principal with read access to the App Service configuration can extract plaintext database credentials.

    Why this is correct

    App Service settings are readable by users with appropriate resource permissions, exposing embedded secrets.

  • The App Service hypervisor becomes vulnerable to guest-to-host breakout.

    Why it's wrong here

    Hypervisor breakouts are independent of application configuration storage.

About these practice questions

Courseiva writes every CPENT question from scratch — 274 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.