CCPenX-Az Certified Cloud Pentesting eXpert - Azure Questions and Answers
You’ve uncovered valid credentials for another user in the previous step. Authenticate as this user and investigate their level of access within the Azure environment. Which of the following Microsoft Entra ID roles is assigned to this user?
A compromised principal has permission to list role assignments. Identify which user has the User Access Administrator role at the resource group scope.
Authenticate to Azure as a service principal using the credentials found in backup-config.json.
Inside the public blob container, a file named backup-config.json contains service principal credentials. What field contains the App Registration client ID?
After gaining access to the Azure tenant, enumerate all resource groups available to the compromised user. One resource group contains the word prod. What is the name of that resource group?
Carefully enumerate the accessible Azure Blob Container to locate a file containing credentials for an App Registration within the tenant. What is the Application/Client ID of the discovered App Registration?