GPEN Azure Apps and Attacks Practice Question
An attacker is performing reconnaissance on an Microsoft Entra ID tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?
⚠ Common exam trap
Candidates frequently look for 'Conditional Access' policies or 'Role-Based Access Control' settings. They miss the specific 'External collaboration settings' menu, which controls global directory visibility for guest users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
External collaboration settings for Guest user access restrictions.
By default, Microsoft Entra ID allows guest users to see other users and groups in the directory. This is a common reconnaissance vector for attackers to map the organization's structure. Restricting this access is a critical step in hardening the tenant, ensuring that guest identities have limited visibility into the internal organizational structure during an initial compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
External collaboration settings for Guest user access restrictions.
Why this is correct
This setting in the Microsoft Entra ID 'External Identities' configuration explicitly controls the visibility of guest users. By setting this to 'Limited access', guests can only see their own profile, which prevents them from enumerating other users, groups, or sensitive directory information.
- ✗
Conditional Access policy for guest users.
Why it's wrong here
Conditional Access policies are used to enforce authentication requirements like MFA or device compliance. They are not designed to restrict directory-level object visibility or read operations, which are controlled by the Global Tenant settings for external identities.
- ✗
The 'Enable Global Reader' role for guests.
Why it's wrong here
The Global Reader role is a powerful administrative role that provides read-only access to all directory information. Assigning this to guests would significantly increase the impact of a compromise rather than remediating it. It is the opposite of the intended security goal.
- ✗
The 'AppRoleAssignmentRequired' property of the tenant.
Why it's wrong here
This property applies to individual application service principals and does not govern directory-wide visibility for guest users. It is a tool for application-level access control, not a mechanism for managing the broader visibility settings of the Microsoft Entra ID directory itself.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.