Courseiva
Azure AD Integration →mediumMultiple Choice

GPEN Azure AD Integration Practice Question

During an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?

⚠ Common exam trap

Candidates often think about password cracking or brute force. They overlook that the signing certificate is the 'root of trust' for federated identities, making it the most critical target.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Compromise of the private signing key allows for the creation of unauthorized authentication tokens.

The token-signing certificate is the foundation of trust in a federated environment. If an attacker compromises the private key of this certificate, they can forge SAML tokens for any user in the directory. This bypasses Multi-Factor Authentication and allows for complete identity impersonation, making the protection of the AD FS server and its associated secrets a critical objective for both defenders and attackers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The certificate is public knowledge and can be used to decrypt all cloud traffic.

    Why it's wrong here

    The public portion of the token-signing certificate is used by the relying party to verify the digital signature of the incoming token, not to encrypt traffic. Decryption of TLS traffic requires the server's private key, which is distinct from the identity token signing keys.

  • ✓

    Compromise of the private signing key allows for the creation of unauthorized authentication tokens.

    Why this is correct

    If the private key is exposed, an attacker can sign fraudulent SAML assertions. These assertions are trusted by Microsoft Entra ID as valid identity claims, effectively allowing the attacker to sign in as any user without needing their password or passing the actual identity provider's authentication checks.

  • ✗

    AD FS requires the certificate to be stored in an unsecured plaintext file on the web server.

    Why it's wrong here

    AD FS stores the token-signing private key within the Windows Certificate Store, specifically protected by the service account's permissions. It does not exist as a plaintext file accessible to web users, requiring elevated privileges or hardware security module (HSM) access to extract or manipulate.

  • ✗

    The relying party cannot verify the identity if the certificate expires.

    Why it's wrong here

    An expired certificate is a stability and operational availability issue rather than a primary security vulnerability. If the certificate expires, authentication will fail globally, leading to a denial-of-service condition for users, but it does not inherently provide an attacker with unauthorized access or privilege escalation.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.