Certified Ethical Hacker (CEH) Practice Question

During a cloud penetration test you exploit an SSRF in a web app running on an EC2 instance. Because the instance still allows IMDSv1, you pull the temporary IAM role credentials and escalate privileges. The developers cannot change the code but still need on-instance metadata access. Which AWS control best blocks this attack path?

  • Configure the instance to require Instance Metadata Service v2 (IMDSv2) and set the hop limit to 1 so only on-instance calls with a valid session token succeed.

  • Remove the IAM role from the EC2 instance and deny the sts:AssumeRole action to every principal except administrators.

  • Disable access to the Instance Metadata Service entirely so the 169.254.169.254 address is unreachable from the instance.

  • Place the web server in a private subnet that has no direct route to the Internet Gateway.

Certified Ethical Hacker (CEH)
Cloud Computing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot