Courseiva
Azure Apps and Attacks →hardMultiple Choice

GPEN Azure Apps and Attacks Practice Question

An attacker has compromised an Azure App Service and obtained the application's managed identity token. They want to use it to access an Azure SQL Database. The managed identity has been granted access to the SQL server. Which of the following is the correct way to authenticate to the SQL Database using the managed identity token?

⚠ Common exam trap

The trap here is assuming that the token can be used as a password in a connection string, which is a common misconception but not how Microsoft Entra ID token authentication works for SQL.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the token in the 'Access Token' property of a SqlConnection object with 'Authentication=Active Directory Access Token'.

The correct method is to use the managed identity's access token directly in the SqlConnection object with 'Authentication=Active Directory Access Token'. The token must be scoped to https://database.windows.net/. This allows the application to authenticate to Azure SQL using the managed identity, leveraging its assigned permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the token to call the Azure SQL REST API to execute queries.

    Why it's wrong here

    Azure SQL does not provide a REST API for executing arbitrary T-SQL queries. While there is a management API for managing SQL resources, it does not allow querying data. Therefore, this method is not viable for accessing the database content.

  • ✗

    Use the token as the password in a SQL connection string with 'Authentication=Active Directory Password'.

    Why it's wrong here

    Azure SQL does not accept an access token as a password in a connection string with 'Active Directory Password' authentication. That method requires a username and password of an Microsoft Entra ID user. Using a token as a password will fail because the authentication mechanism expects a different format and flow.

  • ✓

    Use the token in the 'Access Token' property of a SqlConnection object with 'Authentication=Active Directory Access Token'.

    Why this is correct

    Azure SQL supports Microsoft Entra ID access token authentication via the 'Access Token' property in SqlConnection. The token must be obtained for the resource https://database.windows.net/. This method allows the managed identity to authenticate without a password. It is the correct approach to leverage the token for SQL access.

  • ✗

    Use the token to authenticate to the Azure SQL server's master database and then impersonate a user.

    Why it's wrong here

    You cannot simply authenticate to the master database with a token and then impersonate a user without proper permissions. The token authentication grants access based on the managed identity's permissions, and impersonation requires additional privileges that may not be present. This is not a standard or reliable method.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.