312-50 exam dumps

312-50 practice question 442 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 442

Single answer▪ Cloud Computing Threats

A company migrates several internal applications to a public cloud provider. During a security assessment, an ethical hacker discovers that a storage bucket containing customer documents is accessible over the internet because of an overly permissive access policy. The DevOps team argues that the data is safe because the cloud provider secures the underlying infrastructure. Which issue is being demonstrated in this scenario?

  1. A

    A failure of the cloud provider's physical security controls

  2. B

    A shared responsibility model gap caused by customer misconfiguration

  3. C

    A hypervisor escape vulnerability affecting multitenant isolation

  4. D

    A denial-of-service condition caused by insufficient cloud scalability

Show answer and explanation

Correct answer: B

Explanation

The key concept being tested is the cloud shared responsibility model. Major cloud providers document that they are responsible for securing the underlying infrastructure, while customers are responsible for configuring services securely, including access controls for storage, IAM permissions, network rules, and data protection settings. Misconfigured cloud storage is one of the most common real-world cloud threats because it can expose sensitive data without any sophisticated exploit. In CEH contexts, candidates should recognize that many cloud breaches result from customer-side misconfigurations rather than provider compromise. This aligns with guidance from providers such as AWS, Microsoft Azure, and Google Cloud, all of which emphasize that customers must correctly configure storage access and identity policies to prevent unintended public exposure.

  • A. Incorrect.

    This is incorrect because the scenario does not indicate any compromise of the provider's physical data center protections. The problem is an internet-accessible bucket created through an overly permissive policy, which is a logical configuration issue rather than a physical security failure.

  • B. Correct.

    This is correct. In public cloud environments, providers typically secure the infrastructure of the cloud, while customers are responsible for security in the cloud, including identity, access policies, storage permissions, and data exposure settings. Publicly exposed storage due to permissive ACLs, bucket policies, or similar settings is a classic cloud misconfiguration and a common cloud computing threat.

  • C. Incorrect.

    This is incorrect because a hypervisor escape would involve breaking isolation between virtual machines or tenants through the virtualization layer. Nothing in the scenario suggests VM-to-host compromise, cross-tenant access, or exploitation of the hypervisor. The exposure is due to a storage policy configuration mistake.

  • D. Incorrect.

    This is incorrect because denial-of-service relates to resource exhaustion or service unavailability. The issue described is loss of confidentiality from unauthorized public access to stored data, not reduced availability or autoscaling failure.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam