Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 5Objective 2

Azure Applications and Attack Strategies GPEN Practice Questions (Page 3)

Part of the Cloud and Azure Attacks domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
7concepts

Questions 11–15

  1. 11application · medium

    A Logic App is configured with an HTTP trigger that calls a Microsoft Graph API to read user profiles. The Logic App uses a system-assigned managed identity. You discover that the Logic App's managed identity has been granted the 'User.Read.All' application permission. The Logic App's HTTP trigger is publicly accessible without authentication. What is the primary risk you should report?

    Select an answer first
  2. 12application · medium

    Your company has a web app on Azure App Service that calls an API on a separate App Service. The API is protected by Azure AD. You want to ensure the web app can authenticate to the API without storing credentials. What is the best way to configure this?

    Select an answer first
  3. 13application · medium

    Your company is migrating a legacy web app to Azure App Service. The app currently uses a username/password database for authentication. You want to modernize it to use Azure AD while minimizing changes to the app code. What is the best approach?

    Select an answer first
  4. 14application · medium

    An Azure App Service uses a system-assigned managed identity to access a Key Vault. The Key Vault's access policy grants the managed identity 'Get' and 'List' on secrets. The App Service's application settings use a Key Vault reference for a database password. During a penetration test, you compromise the App Service's code execution. What is the most direct way to retrieve the database password?

    Select an answer first
  5. 15foundation · easy

    In an Azure application, which identity mechanism allows a compute resource (such as a virtual machine or an App Service) to authenticate to Azure services without storing credentials in code or configuration files?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.