exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 62 discussion

Actual exam question from CompTIA's PT0-002
Question #: 62
Topic #: 1
[All PT0-002 Questions]

Which of the following should a penetration tester consider FIRST when engaging in a penetration test in a cloud environment?

  • A. Whether the cloud service provider allows the penetration tester to test the environment
  • B. Whether the specific cloud services are being used by the application
  • C. The geographical location where the cloud services are running
  • D. Whether the country where the cloud service is based has any impeding laws
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ryanzou
Highly Voted 2 years, 7 months ago
Selected Answer: A
Definitely A
upvoted 7 times
...
Gadoof
Most Recent 1 year, 2 months ago
Real world you don't have to let the CSP know that you're going to perform a pentest. Both AWS and Azure have changed their stance on this and you can perform attacks against VM's, containers, etc. You can't attack Azure/AWS services directly even if the client is hosting data there, but you can attack VM's as if they were owned by the client directly. https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing https://aws.amazon.com/security/penetration-testing/
upvoted 1 times
maigoya
9 months, 3 weeks ago
But CSP includes others not just the Public CSPs. I would say A.
upvoted 1 times
...
...
LiveLaughToasterBath
1 year, 4 months ago
Selected Answer: A
https://www.comptia.org/blog/penetration-testing-in-the-cloud#myself The first step as cloud consumers is to understand what level of testing the cloud provider allows. Contracts are the element that defines exactly what we can and can’t do within our cloud service provider. A good contract should specify what level of testing we can perform. It then becomes our responsibility to make sure we adhere to these limits or, if we subcontract penetration testing services, make sure that our vendor understands what our contract says.
upvoted 1 times
...
dave_delete_me
1 year, 4 months ago
I REALLY, REALLY, REALLY want to say “A” is correct but if you think about using your test taking skills, try to understand what the question is TRULY asking. My logic goes like this… the question states "when engaging in a penetration test”, so that means you already have permission from the CSP because you are ALREADY IN THE ACT OF “engaging” THE PEN TEST. So, following this logic, the obvious answer is C. Thoughts anyone?
upvoted 1 times
[Removed]
1 year, 4 months ago
I think the word FIRST gives away CompTIA's hand. Why get cloud service provider permission (not easy) if they're based in <prohibited country>? The again, isn't this from the perspective on an individual pen tester? Now I have confused myself more.
upvoted 1 times
...
...
solutionz
1 year, 9 months ago
Selected Answer: A
When planning a penetration test in a cloud environment, the penetration tester must take several considerations into account. However, the primary concern usually lies in obtaining proper authorization and understanding the scope and boundaries of the test. Among the options provided, the one that should be considered FIRST is: A. **Whether the cloud service provider allows the penetration tester to test the environment**. Cloud environments often share resources among multiple clients, and aggressive testing could inadvertently affect other customers' services. Therefore, it's essential to obtain explicit permission from the cloud service provider, understand their policies, and make sure the testing won't violate any terms of service. Without this clearance, testing might lead to legal consequences or other serious issues. The other options, although important in different contexts or at later stages of planning, are not as critical as ensuring that the testing is allowed by the cloud provider.
upvoted 1 times
...
NBLE
2 years, 1 month ago
Selected Answer: A
A is the answer. First you make sure whether you the CSP will allow you to conduct the penetration test, and then (answers C & D) can check the location of the CSP and see if there is any new legislature you must comply to.
upvoted 1 times
...
xviruz2kx
2 years, 1 month ago
A. Whether the cloud service provider allows the penetration tester to test the environment should be considered first when engaging in a penetration test in a cloud environment. Before conducting any penetration testing in a cloud environment, it is essential to check the terms and conditions of the cloud service provider. Many cloud service providers prohibit penetration testing or have specific rules and restrictions that must be followed. Therefore, the first step is to check whether the cloud service provider allows penetration testing. Option B, "whether the specific cloud services are being used by the application," is an important consideration but should come after ensuring that the cloud service provider allows penetration testing. Option C, "the geographical location where the cloud services are running," is important for compliance and data protection purposes, but it is not the first consideration when engaging in a penetration test. Option D, "whether the country where the cloud service is based has any impeding laws," is also an important consideration, but again, it should come after ensuring that the cloud service provider allows penetration testing.
upvoted 1 times
...
AaronS1990
2 years, 1 month ago
This is a tough one as you could make a case for A or C. Personally I think C. If a cloud company said yes and I assumed I could Pentest I could end up in a lot of trouble if I unknowingly violated international laws. If I checked that I could pentest the location based on geographical laws and it was a yes and then the company said no... i'd be in no trouble. For me the international/geographical limitations are the easier area to slip up in so I think CompTIA is trying to get us to make sure we always consider it. If anyone has the pentest+ book then i'm sure the naswer is very simple but i'm using UDemy
upvoted 2 times
...
[Removed]
2 years, 2 months ago
A is correct answer
upvoted 1 times
...
nickwen007
2 years, 2 months ago
The first thing a penetration tester should consider when engaging in a penetration test in a cloud environment is A. Whether the cloud service provider allows the penetration tester to test the environment. Before conducting any tests, it is important to ensure that the cloud service provider allows the penetration tester to conduct tests against the environment. If they do not, then all tests must be conducted in accordance with the provider's terms and conditions.
upvoted 2 times
...
beamage
2 years, 2 months ago
Selected Answer: C
The Books Says C is Correct
upvoted 1 times
...
masso435
2 years, 5 months ago
Selected Answer: A
C is to be considered as well. I think you can ask either first. If you can't pentest due to the geographical location then it doesn't matter if the cloud service provider allows it and vice versa. But I'll go with A in this case. I think it's tricky to ask that questions with both those are required to know before proceeding.
upvoted 4 times
...
Gargomel
2 years, 6 months ago
Selected Answer: C
I think the answer is the geographical location. Because knowing that determines whether you can PenTest, which tools you're allowed to use, and the information policies that dictate the administrative controls for the baseline of the PenTest.
upvoted 2 times
...
petercorn
2 years, 7 months ago
Selected Answer: A
During pre-engagement activities and discussions, verify if there are any resources that are in the cloud, because you will need to get authorization from the cloud provider to perform a pentest on the cloud resources.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...