GPEN › Azure Apps and Attacks
This domain covers attacking and auditing Microsoft Entra ID application identities and Azure compute resources. Candidates query Microsoft Graph, inspect App Registrations and service principals, abuse managed identities, and trace how Logic Apps, App Services, and storage accounts expose tokens or workflow definitions during an engagement.
GPEN Azure Apps and Attacks — All 29 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning