During a black-box assessment, you exploit an SSRF flaw on an EC2-hosted application that has Instance Metadata Service version 2 enabled. After obtaining a session token with a PUT request to /latest/api/token, which HTTP request header must you include when you query /latest/meta-data/iam/security-credentials/ to capture the role's temporary keys?
IMDSv2 requires a two-step process. First, a PUT request to /latest/api/token returns a time-limited session token. Every subsequent GET request to metadata endpoints must include that token in the header field named "X-aws-ec2-metadata-token". If the header is missing or mis-named, the service responds with HTTP 401. Headers such as "Authorization", "X-IMDS-Session-ID", or "X-aws-security-token" are not recognized by IMDSv2 for this purpose, so the metadata request would fail and no temporary credentials would be exposed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SSRF and how does it work?
Open an interactive chat with Bash
What is AWS EC2 Instance Metadata Service (IMDS)?
Open an interactive chat with Bash
Why does IMDSv2 use a session token, and how does it improve security?
Open an interactive chat with Bash
What is SSRF and how does it work?
Open an interactive chat with Bash
What is the Instance Metadata Service (IMDS) and how does IMDSv2 improve security?
Open an interactive chat with Bash
Why do temporary security credentials matter in a cloud environment?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Cloud Computing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .