Courseiva

GPEN · domain

Azure Apps and Attacks

This domain covers attacking and auditing Microsoft Entra ID application identities and Azure compute resources. Candidates query Microsoft Graph, inspect App Registrations and service principals, abuse managed identities, and trace how Logic Apps, App Services, and storage accounts expose tokens or workflow definitions during an engagement.

11 questions1 easy6 medium4 hard

Focused practice

Practice Azure Apps and Attacks questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Azure Apps and Attacks

Be able to enumerate Entra ID app identities with Microsoft Graph, assess credential and token validity, and pivot from a compromised Azure workload using its managed identity. The critical point is matching token audience and permissions to the target resource before attempting access.

Querying Microsoft Graph for service principals, appRoleAssignmentRequired, and app role assignments

Analyzing App Registration credentials, expired client secrets, and still-valid refresh tokens

Abusing managed identity tokens from App Service or Logic App to reach Azure SQL Database

Reviewing publicly accessible storage accounts holding Logic App workflow definitions

Watch out for

Common Azure Apps and Attacks exam traps

  • ▸Assuming an expired client secret invalidates existing refresh tokens; refresh tokens can remain usable after secret expiry.
  • ▸Treating appRoleAssignmentRequired=false as harmless; it can allow users or groups to access the app without explicit assignment.
  • ▸Forgetting that managed identity tokens are audience-scoped, so a token for one resource cannot be replayed against Azure SQL or Graph.

Question index

All Azure Apps and Attacks questions (11)

Click any question to see the full explanation, or start a practice session above.

1

An attacker has gained access to an Azure VM and wants to escalate privileges by abusing the VM's managed identity. The managed identity has the 'Contributor' role on the subscription. Which of the following actions would allow the attacker to add a new user to an Azure AD group that has 'Global Administrator' role?

Hard
2

A penetration tester is assessing an Azure environment and discovers a function app with an HTTP trigger that does not require authentication. The function app has a system-assigned managed identity with Contributor role on the subscription. What is the most immediate risk?

Easy
3

When conducting a penetration test on an Azure App Service, you discover an 'environment.js' file in the public directory containing a 'CLIENT_ID'. What is the risk associated with this finding?

Medium
4

Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What security implication does this setting present for enterprise applications?

Medium
5

An attacker is performing reconnaissance on an Azure AD tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?

Medium
6

During an Azure penetration test, you discover an App Registration with an expired client secret that still has active refresh tokens issued prior to expiration. The application holds high-privilege directory roles. How do these leaked refresh tokens behave regarding Azure AD security boundaries?

Medium
7

An attacker has obtained a refresh token for an Azure AD application with the 'Mail.Read' delegated permission. The token was issued to a user who has since had their password reset and all refresh tokens revoked. The attacker attempts to use the refresh token to obtain a new access token. What is the expected outcome?

Hard
8

An attacker has compromised an Azure App Service and obtained the application's managed identity token. They want to use it to access an Azure SQL Database. The managed identity has been granted access to the SQL server. Which of the following is the correct way to authenticate to the SQL Database using the managed identity token?

Hard
9

During an Azure penetration test, you gain access to a Linux VM in a subnet that has a user-defined route forcing all traffic through a Network Virtual Appliance (NVA). You want to reach the Azure Instance Metadata Service (IMDS) to steal managed identity tokens. Which of the following best describes how you can access IMDS from this VM?

Medium
10

Which of the following describes the risk of 'App Role' over-assignment in Azure AD?

Medium
11

A penetration tester is reviewing an Azure Logic App that uses a managed identity to access an Azure SQL Database. The tester finds that the Logic App's workflow definition is stored in a storage account that is publicly accessible. The workflow includes a step that executes a stored procedure with parameters. Which of the following is the most significant risk of this misconfiguration?

Hard

Frequently asked questions

What does the Azure Apps and Attacks domain cover on the GPEN exam?
Be able to enumerate Entra ID app identities with Microsoft Graph, assess credential and token validity, and pivot from a compromised Azure workload using its managed identity. The critical point is matching token audience and permissions to the target resource before attempting access.
How many questions are in this domain?
This page lists all 11 Azure Apps and Attacks questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Azure Apps and Attacks questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN azure apps and attacks Practice Questions