312-50 exam dumps

312-50 practice question 432 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 432

Single answer▪ Cloud Computing Concepts

A company asks a CEH-certified security consultant to assess a newly deployed web application hosted in a public cloud environment. During the reconnaissance phase, the consultant discovers that the application stores uploaded files in an object storage bucket and serves some of them directly to users over HTTPS. The consultant suspects the organization may have accidentally exposed sensitive files due to a cloud misconfiguration. Which action would be the MOST appropriate initial step to validate this risk without disrupting production services or exceeding an authorized assessment scope?

  1. A

    Enumerate the bucket's access controls and attempt to retrieve only a known non-sensitive test object through its public URL or approved methods

  2. B

    Launch a password-spraying attack against the cloud tenant's administrative portal to confirm whether weak credentials contributed to the exposure

  3. C

    Modify the bucket policy to temporarily deny public access and observe whether the application breaks, confirming the bucket was exposed

  4. D

    Exploit the application server to obtain cloud instance metadata credentials and then review the storage configuration from the management plane

Show answer and explanation

Correct answer: A

Explanation

This question tests practical application of cloud computing concepts in an ethical hacking context, especially the distinction between cloud misconfiguration validation and intrusive exploitation. Public cloud object storage services commonly support public access when explicitly or accidentally configured, and assessing that exposure should begin with non-destructive validation. Best practice in security assessments is to use the least invasive technique that can answer the assessment question while staying within scope. Relevant vendor guidance includes AWS documentation on S3 Block Public Access and bucket policies, Microsoft guidance on Azure Blob anonymous access settings, and Google Cloud documentation on IAM and public access prevention for Cloud Storage. Across providers, the key concept is that misconfigured storage permissions can expose data without requiring credential theft or server compromise, so the initial step should focus on safe verification of effective access.

  • A. Correct.

    Correct. In a cloud security assessment, the least intrusive and most defensible first step is to validate whether the object storage bucket is publicly accessible by reviewing its effective access controls and attempting to access only an approved, non-sensitive object. This approach aligns with standard rules of engagement, minimizes operational risk, and directly tests the suspected exposure. In real environments such as Amazon S3, Azure Blob Storage, or Google Cloud Storage, misconfigured public read access is a common issue, and validating exposure through authorized, low-impact access is appropriate.

  • B. Incorrect.

    Incorrect. Password spraying against the administrative portal is a much more aggressive activity, may fall outside scope, and does not directly validate whether the storage bucket itself is publicly exposed. It also introduces unnecessary risk and could trigger account lockouts or alerts. This option reflects the misconception that all cloud issues should be approached through account compromise rather than configuration validation.

  • C. Incorrect.

    Incorrect. Changing the bucket policy in production is not an appropriate initial validation step because it alters the client environment and may cause a service outage. Ethical hackers should avoid modifying configurations unless explicitly authorized for that purpose and unless the test plan calls for controlled changes. The goal at this stage is to observe and validate, not remediate or disrupt.

  • D. Incorrect.

    Incorrect. Attempting to exploit the application server to steal instance metadata credentials is intrusive and unnecessary for confirming simple public exposure of cloud object storage. While instance metadata abuse is a real cloud attack path, using it here would exceed the minimal-action principle and likely go beyond the initial objective. The misconception is assuming that privilege escalation is required before checking for basic storage misconfigurations.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam