
GIAC Penetration Tester (GPEN)
Domain 5Objective 1
Azure Overview, Attacks, and AD Integration GPEN Practice Questions (Page 4)
Part of the Cloud and Azure Attacks domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
10concepts
Questions 16–20
- 16
A company wants to detect password spraying attacks against their Azure AD tenant. Which of the following configurations is most effective?
Select an answer first - 17
Which Azure AD persistence technique involves creating a new user account with administrative privileges that is not subject to normal monitoring?
Select an answer first - 18
Which Azure AD monitoring feature provides a report of sign-in attempts that can be used to detect password spraying or token replay attacks?
Select an answer first - 19
According to the shared responsibility model in Microsoft Azure, which of the following is the customer responsible for when using an Azure virtual machine?
Select an answer first - 20
An attacker has compromised a Global Administrator account in Azure AD. They want to maintain access even if the account is disabled or the password is changed. Which of the following is the most effective persistence technique?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.