ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 292 - PT0-002 discussion

Report
Export

During the assessment of a client's cloud and on-premises environments, a penetration tester was able to gain ownership of a storage object within the cloud environment using the..... premises credentials. Which of the following best describes why the tester was able to gain access?

A.
Federation misconfiguration of the container
Answers
A.
Federation misconfiguration of the container
B.
Key mismanagement between the environments
Answers
B.
Key mismanagement between the environments
C.
laaS failure at the provider
Answers
C.
laaS failure at the provider
D.
Container listed in the public domain
Answers
D.
Container listed in the public domain
Suggested answer: A

Explanation:

The best explanation for why the tester was able to gain access to the storage object within the cloud environment using the on-premises credentials is federation misconfiguration of the container.

Federation is a process that allows users to access multiple systems or services with a single set of credentials, by using a trusted third-party service that authenticates and authorizes the users.

Federation can enable seamless integration between cloud and on-premises environments, but it can also introduce security risks if not configured properly. Federation misconfiguration of the container can allow an attacker to access the storage object with the on-premises credentials, if the container trusts the on-premises identity provider without verifying its identity or scope. The other options are not valid explanations for why the tester was able to gain access to the storage object within the cloud environment using the on-premises credentials. Key mismanagement between the environments is not relevant to this issue, as it refers to a different scenario involving encryption keys or access keys that are used to protect or access data or resources in cloud or on-premises environments. IaaS failure at the provider is not relevant to this issue, as it refers to a different scenario involving infrastructure as a service (IaaS), which is a cloud service model that provides virtualized computing resources over the internet. Container listed in the public domain is not relevant to this issue, as it refers to a different scenario involving container visibility or accessibility from public networks or users.

asked 02/10/2024
Salih Igde
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first