Courseiva
Cloud And Hybrid Infrastructure SecurityhardMultiple ChoiceObjective-mapped

CPENT Cloud And Hybrid Infrastructure Security Practice Question

A penetration tester is evaluating a hybrid Active Directory environment. They compromise an on-premises user account that has been synchronized to Azure AD. They discover that the on-premises account is a member of a high-privilege local group, but Azure AD Connect has filtered out this group synchronization. How can the tester leverage Azure AD Connect configuration weaknesses?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Examine Azure AD Connect synchronization rules and connector filters for misconfigurations or export rules that might inadvertently expose directory objects or allow rule manipulation.

If Azure AD Connect synchronization rules or filtering configurations are misconfigured, attackers can sometimes modify object attributes or take advantage of synchronization sync cycles to escalate privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use the Azure AD Connect database password stored in the local SQL Express instance to perform a DCShadow attack.

    Why it's wrong here

    DCShadow requires domain administrator rights on-premises, not the AD Connect SQL password.

  • Force Azure AD Connect to disable multi-factor authentication for all cloud administrators.

    Why it's wrong here

    AD Connect does not control cloud MFA enforcement.

  • Examine Azure AD Connect synchronization rules and connector filters for misconfigurations or export rules that might inadvertently expose directory objects or allow rule manipulation.

    Why this is correct

    AD Connect custom sync rules and filters can be audited for misconfigurations that impact hybrid security boundaries.

  • Inject a malicious DLL into the Azure AD Connect health agent service to execute arbitrary code on the Azure cloud domain controller.

    Why it's wrong here

    Azure AD Connect health agents communicate outbound and do not host cloud domain controllers.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every CPENT question from scratch — 274 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.