Be able to enumerate Entra ID app identities with Microsoft Graph, assess credential and token validity, and pivot from a compromised Azure workload using its managed identity. The critical point is matching token audience and permissions to the target resource before attempting access.
Start practicing
Azure Apps and Attacks — choose a session length
Free · No account required
Domain overview
This domain covers attacking and auditing Microsoft Entra ID application identities and Azure compute resources. Candidates query Microsoft Graph, inspect App Registrations and service principals, abuse managed identities, and trace how Logic Apps, App Services, and storage accounts expose tokens or workflow definitions during an engagement.
Exam objectives
Querying Microsoft Graph for service principals, appRoleAssignmentRequired, and app role assignments
Analyzing App Registration credentials, expired client secrets, and still-valid refresh tokens
Abusing managed identity tokens from App Service or Logic App to reach Azure SQL Database
Reviewing publicly accessible storage accounts holding Logic App workflow definitions
Assuming an expired client secret invalidates existing refresh tokens; refresh tokens can remain usable after secret expiry.
Treating appRoleAssignmentRequired=false as harmless; it can allow users or groups to access the app without explicit assignment.
Forgetting that managed identity tokens are audience-scoped, so a token for one resource cannot be replayed against Azure SQL or Graph.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An attacker is performing reconnaissance on an Azure AD tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?
2When conducting a penetration test on an Azure App Service, you discover an 'environment.js' file in the public directory containing a 'CLIENT_ID'. What is the risk associated with this finding?
3Which of the following describes the risk of 'App Role' over-assignment in Azure AD?
4During an Azure penetration test, you discover an App Registration with an expired client secret that still has active refresh tokens issued prior to expiration. The application holds high-privilege directory roles. How do these leaked refresh tokens behave regarding Azure AD security boundaries?
5Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What security implication does this setting present for enterprise applications?
6During an Azure penetration test, you gain access to a Linux VM in a subnet that has a user-defined route forcing all traffic through a Network Virtual Appliance (NVA). You want to reach the Azure Instance Metadata Service (IMDS) to steal managed identity tokens. Which of the following best describes how you can access IMDS from this VM?
7An attacker has compromised an Azure App Service and obtained the application's managed identity token. They want to use it to access an Azure SQL Database. The managed identity has been granted access to the SQL server. Which of the following is the correct way to authenticate to the SQL Database using the managed identity token?
8An attacker has obtained a refresh token for an Azure AD application with the 'Mail.Read' delegated permission. The token was issued to a user who has since had their password reset and all refresh tokens revoked. The attacker attempts to use the refresh token to obtain a new access token. What is the expected outcome?
9A penetration tester is assessing an Azure environment and discovers a function app with an HTTP trigger that does not require authentication. The function app has a system-assigned managed identity with Contributor role on the subscription. What is the most immediate risk?
10An attacker has gained access to an Azure VM and wants to escalate privileges by abusing the VM's managed identity. The managed identity has the 'Contributor' role on the subscription. Which of the following actions would allow the attacker to add a new user to an Azure AD group that has 'Global Administrator' role?
11A penetration tester is reviewing an Azure Logic App that uses a managed identity to access an Azure SQL Database. The tester finds that the Logic App's workflow definition is stored in a storage account that is publicly accessible. The workflow includes a step that executes a stored procedure with parameters. Which of the following is the most significant risk of this misconfiguration?
Be able to enumerate Entra ID app identities with Microsoft Graph, assess credential and token validity, and pivot from a compromised Azure workload using its managed identity. The critical point is matching token audience and permissions to the target resource before attempting access.
The Courseiva GPEN question bank contains 11 questions in the Azure Apps and Attacks domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Azure Apps and Attacks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included