The SecOps Group CCPenX-Az 試験概要:
| 認定ベンダー: | The SecOps Group |
|---|---|
| 試験名: | Certified Cloud Pentesting eXpert - Azure |
| 試験番号: | CCPenX-Az |
| 対応言語: | 英語 |
| 試験形式: | 実務に即した攻撃手順のシミュレーション, VPN接続が必要, 実習環境を使用, 実践的なCTF形式 |
| 合格点: | 公表されていません |
| 認定の有効期間: | 3年間 |
| 試験時間: | 420 分 |
| 出題数: | シナリオ形式の課題(設問数は固定されていません) |
| 関連資格: | CRTeamerX CAPenX CCPenX-AWS C-ADPenX |
| 受験料: | 400.00ポンド / 約510米ドル(プロモーション価格:100.00ポンド / 約127米ドル) |
| 推奨トレーニング: | The SecOps Group 公式学習リソース Azureにおける攻撃的セキュリティに関するガイド |
| 受験申し込み: | 公式登録ページ |
| サンプル問題: | The SecOps Group CCPenX-Az サンプル問題 |
| 受験方法: | オンライン監督付きまたはいつでも受験可能な方式で実施。VPN経由でリモートから実施し、制限時間内であれば自分のペースで進められます |
| 前提条件: | 推奨条件:5年以上の実務におけるペネトレーションテスト経験、12か月以上のAzureまたはクラウドセキュリティに関する実務経験。受験に必須の前提条件は定められていません |
| 公式シラバスのURL: | https://pentestingexams.com/certifications/expert/certified-cloud-pentesting-expert-azure/ |
The SecOps Group CCPenX-Az 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: 偵察と列挙 | 20% | - Azureリソースの検出 - Azureテナントおよびドメインの情報収集 - DNS、エンドポイント、公開されているサービスのマッピング - Entra ID(Azure AD)の情報収集 |
| トピック 2: 攻撃後の操作と持続的なアクセスの確保 | 15% | - データの収集および外部への流出手法 - 持続的なアクセス権の維持 - 一連の攻撃手順の実演 - Azure環境における防御機構の回避 |
| トピック 3: 権限昇格 | 25% | - Key Vaultおよび機密情報管理における設定ミスの悪用 - サービスプリンシパルおよびアプリ登録に対する攻撃 - Entra IDのロールおよび権限の不正利用 - Managed Identityの悪用 |
| トピック 4: 初期アクセスの確保 | 20% | - 同意フィッシングおよびアプリケーションの不正利用 - パスワードスプレー攻撃および認証情報の総当たり攻撃 - 公開された機密情報および設定上の不備の悪用 - トークンおよびセッション情報の不正利用 |
| トピック 5: 権限の横展開とテナントの制御権獲得 | 20% | - APIおよびAzure管理エンドポイントの悪用 - 複数リソースおよびサブスクリプション間の移動 - ハイブリッドIDおよびオンプレミス環境との連携機能の不正利用 - コンピューティングリソース、ストレージ、ネットワークを経由した侵入経路の確保 |
The SecOps Group Certified Cloud Pentesting eXpert - Azure 認定 CCPenX-Az 試験問題:
問題 #1
You have been given a breached Azure user credential for an authorized lab tenant:
[email protected]
After logging in, identify the Azure Tenant ID and Subscription ID associated with the account.
問題 #2
Carefully enumerate the accessible Azure Blob Container to locate a file containing credentials for an App Registration within the tenant. What is the Application/Client ID of the discovered App Registration?
問題 #3
Using the previously gained access to the Azure environment, extract an access token from the Web App's environment and use it to impersonate its Managed Identity. Which of the following roles is assigned to the Web App's Security Principal?
A. AppService-Auditor
B. Compute-Instance-Inspector
C. VM-Metadata-Reader
D. Storage-Metadata-Reader
問題 #4
A storage account allows public blob access. Enumerate containers and identify the public container that exposes backup files.
解説:
| 問題 #1 正解: 会員のみ閲覧可能 | 問題 #2 正解: 会員のみ閲覧可能 | 問題 #3 正解: A | 問題 #4 正解: 会員のみ閲覧可能 |














1520 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
