Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 5Objective 1

Azure Overview, Attacks, and AD Integration GPEN Practice Questions (Page 8)

Part of the Cloud and Azure Attacks domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 4–7 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
10concepts

Questions 36–39

  1. 36application · medium

    A company wants to implement a phishing-resistant authentication method for their Azure AD users. They currently use passwords and SMS-based MFA. Which of the following should they implement?

    Select an answer first
  2. 37foundation · easy

    Which Azure Resource Manager attack involves an attacker exploiting overly broad permissions on a resource group to create additional resources or modify existing ones?

    Select an answer first
  3. 38application · hard

    During an Azure penetration test, you discover that a user account has the 'Contributor' role on a subscription. The user does not have any other Azure AD roles. You want to gain access to the Azure AD tenant. Which technique is most likely to achieve this?

    Select an answer first
  4. 39foundation · easy

    What is the primary purpose of an Azure Active Directory tenant?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GPEN

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.