Courseiva
Cloud And Hybrid Infrastructure SecurityhardMultiple SelectObjective-mapped

CPENT Cloud And Hybrid Infrastructure Security Practice Question

A penetration tester is evaluating AWS IAM policies for privilege escalation paths. Which THREE of the following IAM action combinations enable direct or indirect privilege escalation in an AWS environment? (Choose THREE)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

ec2:RunInstances combined with iam:PassRole allowing assignment of high-privilege IAM roles to newly launched instances.

iam:CreateAccessKey, iam:PutUserPolicy, and iam:PassRole combined with compute actions allow privilege escalation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • cloudwatch:PutMetricData combined with logs:CreateLogGroup.

    Why it's wrong here

    CloudWatch and log group permissions are monitoring-related and do not escalate IAM privileges.

  • s3:GetObject combined with s3:PutObject on non-sensitive S3 buckets.

    Why it's wrong here

    Basic S3 read/write permissions do not inherently grant IAM privilege escalation.

  • ec2:RunInstances combined with iam:PassRole allowing assignment of high-privilege IAM roles to newly launched instances.

    Why this is correct

    Passing privileged roles to EC2 instances allows extracting credentials and escalating privileges.

  • iam:CreateAccessKey combined with iam:UpdateAccessKey on an administrator user account.

    Why this is correct

    Creating and updating access keys for admin users allows taking over their identity.

  • iam:PutUserPolicy or iam:PutRolePolicy granting administrative permissions to a user or role controlled by the attacker.

    Why this is correct

    Inline policy creation allows self-granting administrator permissions.

  • rds:DescribeDBInstances combined with ec2:DescribeSecurityGroups.

    Why it's wrong here

    Describe actions are read-only and do not allow privilege escalation.

About these practice questions

This CPENT question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.