Certified Ethical Hacker (CEH) Practice Question

During a web application assessment you discover a server-side request forgery flaw that lets you issue HTTP requests from an Amazon EC2 instance. Your first probe to http://169.254.169.254/latest/meta-data/iam/security-credentials/ is answered with HTTP/1.1 401 Unauthorized and the response header X-Aws-Ec2-Metadata-Token-Required: true. Which hardening measure on the instance is blocking your attempt to steal temporary AWS credentials?

  • The EC2 instance profile has been restricted to read-only S3 access, preventing exposure of credentials.

  • The instance's IAM role has been detached, eliminating any credentials to return from the metadata service.

  • A VPC endpoint policy is denying access to the EC2 service from the instance subnet.

  • Instance Metadata Service Version 2 (IMDSv2) has been enforced, so a session token must be obtained before metadata can be retrieved.

Certified Ethical Hacker (CEH)
Cloud Computing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot