The SecOps Group CCPenX-Az Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Angriffsflächen und Aufklärung in der Azure-Cloud | - Erfassung der Azure-Umgebung und Erkennung von Ressourcen - Aufklärung von Identitäten und Mandanten (Entra ID) |
| Azure-Speicher und Datenexfiltration | - Ausnutzung von Fehlkonfigurationen im Blob-Speicher - Erkennung und Extraktion sensibler Daten |
| Angriffsketten in der Cloud und praxisnahe Szenarien | - Zielerreichung im Stil von Flag-basierten CTF-Wettbewerben - Mehrstufige Angriffsabläufe in Azure-Umgebungen |
| Angriffe auf Azure Active Directory (Entra ID) | - Berechtigungsausweitung in Entra ID - Ausnutzung von Fehlkonfigurationen in Identitätsdiensten |
| Ausnutzung von Schwachstellen in der Azure-Infrastruktur | - Kompromittierung virtueller Maschinen und laterale Ausbreitung - Missbrauch von Netzwerksicherheitsgruppen und virtuellen Netzwerken |
The SecOps Group Certified Cloud Pentesting eXpert - Azure CCPenX-Az Prüfungsfragen mit Lösungen
Using a discovered SAS token with read/list permissions, enumerate blobs inside the sensitive-exports container. Which file contains credentials?
Lösung anzeigen Diskussion 0Antwort:
See the Answer in Explanation below.
Explanation:
service-principal-creds.json
Detailed Solution:
Set variables:
ACCOUNT= " prodreportstore01 "
CONTAINER= " sensitive-exports "
SAS= " ?sv=2025-01-05 & ss=b & srt=sco & sp=rl & se=2026-08-01T00:00:00Z & sig= < signature > " List blobs:
az storage blob list \
--account-name " $ACCOUNT " \
--container-name " $CONTAINER " \
--sas-token " $SAS " \
--query " [].name " \
--output table
Expected output:
Name
----------------------------
monthly-report.csv
service-principal-creds.json
readme.txt
The credential file is:
service-principal-creds.json
================
You are reviewing Azure Activity Logs after a lab compromise. Which operation indicates that an attacker reset another user's password through Microsoft Entra ID?
- A. Microsoft.KeyVault/vaults/secrets/read
- B. Update user / password profile modification
- C. Microsoft.Authorization/roleAssignments/write
- D. Microsoft.Storage/storageAccounts/listKeys/action
Antwort: B 🗳️
Erklärung: (Nur für DeutschPrüfung-Mitglieder sichtbar)
A virtual machine has a system-assigned managed identity. From the VM shell, which Azure CLI command authenticates using that identity?
- A. az login --identity
- B. az account get-access-token --tenant
- C. az login --service-principal
- D. az ad signed-in-user show
Antwort: A 🗳️
Erklärung: (Nur für DeutschPrüfung-Mitglieder sichtbar)
During App Service enumeration, you discover that the compromised user can read App Service application settings. Find the hidden flag stored in the application settings.
Lösung anzeigen Diskussion 0Antwort:
See the Answer in Explanation below.
Explanation:
Flag{app_settings_should_not_store_secrets}
Detailed Solution:
Query App Service settings:
az webapp config appsettings list \
--name finance-reporting-api \
--resource-group rg-prod-apps-eastus \
--output json
Search for suspicious keys:
az webapp config appsettings list \
--name finance-reporting-api \
--resource-group rg-prod-apps-eastus \
--query " [?contains(name, ' FLAG ' ) || contains(name, ' Flag ' ) || contains(name, ' SECRET ' )] " \
--output table
Expected output:
Name SlotSetting Value
---------- ------------- ----------------------------------------
APP_FLAG False Flag{app_settings_should_not_store_secrets}
The flag is:
Flag{app_settings_should_not_store_secrets}






858 Kundenbewertungen

