
GIAC Penetration Tester (GPEN)
Domain 5Objective 1
Azure Overview, Attacks, and AD Integration GPEN Practice Questions (Page 1)
Part of the Cloud and Azure Attacks domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
10concepts
Questions 1–5
- 1
Which technique allows an attacker to use a compromised Azure AD token to access multiple cloud applications without re-authenticating?
Select an answer first - 2
A security team wants to detect token theft and replay attacks in their Azure AD environment. They have enabled MFA and use conditional access. Which of the following monitoring and detection controls is most effective for identifying token replay?
Select an answer first - 3
Which Azure AD role, if compromised, would allow an attacker to reset passwords and manage conditional access policies?
Select an answer first - 4
An organization uses Azure AD with password hash sync and has enabled MFA for all users. A security analyst notices a series of failed sign-ins from a single IP address across many different user accounts, each with a common password such as 'Winter2024!'. The sign-ins are coming from a non-corporate IP range. What is the most likely attack, and what control would best mitigate it?
Select an answer first - 5
Which Azure AD feature is specifically designed to synchronize identities from an on-premises Active Directory to Azure AD?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.