Free The SecOps Group CCPENX-AZ Practice Test Questions and Answers (2026)
Last Update Check
Q: 1
SIMULATION
Authenticate to Azure as a service principal using the credentials found in backup-config.json.
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
SIMULATION
A compromised principal has permission to list role assignments. Identify which user has the User
Access Administrator role at the resource group scope.
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
SIMULATION
With access to the Web App’s Managed Identity, you can now query certain Azure Resources. Use
this access to uncover the hidden secret left behind during provisioning. What is the secret?
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
SIMULATION
After gaining access to the Azure tenant, enumerate all resource groups available to the
compromised user. One resource group contains the word prod. What is the name of that resource
group?
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
SIMULATION
A storage account allows public blob access. Enumerate containers and identify the public container
that exposes backup files.
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
You’ve uncovered valid credentials for another user in the previous step. Authenticate as this user
and investigate their level of access within the Azure environment. Which of the following Microsoft
Entra ID roles is assigned to this user?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Using the managed identity principal ID discovered in the previous task, identify which Azure RBAC
role is assigned to it.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
Inside the public blob container, a file named backup-config.json contains service principal
credentials. What field contains the App Registration client ID?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
The compromised service principal has Contributor access to a resource group but no direct Key Vault
data-plane role. Can it immediately read Key Vault secret values?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
After authenticating as the service principal, enumerate its assigned Azure RBAC role. Which role
does it have?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20