20+ practice questions focused on Azure Apps and Attacks — one of the most tested topics on the GIAC Penetration Tester exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Azure Apps and Attacks PracticeAn attacker has compromised an Azure AD application with the 'User.Read.All' delegated permission. They seek to elevate privileges by abusing the 'onBehalfOf' flow. What is the primary requirement for this attack to succeed?
Explanation: The on-behalf-of flow allows a middle-tier application to exchange a user's token for a new token to access downstream services. Attackers exploit this by tricking a user into authenticating to a malicious app, which then uses the captured token to impersonate the user against sensitive APIs. Understanding this flow is critical for assessing how delegated permissions can be escalated beyond the initial scope intended by the service principal.
Which TWO of the following actions are necessary for an attacker to perform a 'Consent Phishing' attack against an Azure AD tenant?
Explanation: Consent phishing involves tricking users into granting malicious applications permissions to their data. The attacker must register an application in an Azure tenant and then convince users to authorize it. This bypasses conditional access policies if the attacker uses an app that users are permitted to consent to, making it a highly effective technique for persistent access in cloud environments without requiring administrative credentials.
Refer to the exhibit. Which security implication does this application configuration have regarding access control?
Explanation: The setting 'AppRoleAssignmentRequired' set to true forces the application to verify that a user has been explicitly assigned to the application via an AppRoleAssignment. This is a critical security control that prevents any user in the tenant from accessing the application by default, mitigating unauthorized access even if the application is multi-tenant and the user is authenticated.
An attacker finds an Azure Function with an improperly secured HTTP trigger. They want to enumerate the environment variables of the function. Which path is the most likely target for this enumeration?
Explanation: Azure Functions store configuration as environment variables, which are accessible to the process running the code. In vulnerable implementations where the function exposes sensitive data or allows for arbitrary code execution, an attacker can use the Kudu API or local environment inspection to read these variables, often uncovering database connection strings, API keys, or Managed Identity tokens that facilitate further lateral movement.
A developer has assigned a User-Assigned Managed Identity to an Azure App Service. The attacker successfully gains local file access to the App Service instance. How can they obtain an OAuth token for the Azure Resource Manager (ARM) API?
Explanation: Managed Identities provide an IMDS (Instance Metadata Service) endpoint at 169.254.169.254. By making a crafted request to this endpoint with the correct identity headers, an attacker can retrieve a valid OAuth access token for any resource, including ARM. This is a common post-exploitation technique where the attacker pivots from the App Service identity to perform management actions against the broader Azure subscription.
+15 more Azure Apps and Attacks questions available
Practice all Azure Apps and Attacks questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Azure Apps and Attacks. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Azure Apps and Attacks questions on the GPEN frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Azure Apps and Attacks is tested as part of the GIAC Penetration Tester blueprint. Practicing with targeted Azure Apps and Attacks questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GPEN practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Azure Apps and Attacks is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Azure Apps and Attacks practice session with instant scoring and detailed explanations.
Start Azure Apps and Attacks Practice →