GPEN Azure AD Integration Practice Question
During an internal penetration test of a hybrid Microsoft Entra ID environment, you compromise a standard on-premises user account. You notice that the account's on-premises userPrincipalName is jdoe@corp.local, but the corresponding cloud account has the userPrincipalName jdoe@corp.com. Which attribute should you modify on-premises to change the cloud sign-in address for this synchronized user?
⚠ Common exam trap
Watch out — candidates often confuse the mail attribute or proxyAddresses with the userPrincipalName, assuming that email-related attributes control the cloud sign-in address.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
userPrincipalName
In a hybrid Microsoft Entra ID environment, the on-premises userPrincipalName attribute is synchronized to the cloud as the user's sign-in name, provided the domain is verified. Changing this attribute to the desired cloud UPN will update the cloud sign-in address after synchronization. Other attributes like proxyAddresses, mail, and sAMAccountName do not control the cloud UPN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
sAMAccountName
Why it's wrong here
sAMAccountName is the legacy on-premises logon name and is synchronized to Microsoft Entra ID as the user's on-premises SAM account name, but it is not used as the cloud UPN. Modifying it will not change the cloud sign-in address. Therefore, it is not the correct attribute for this scenario.
- ✗
proxyAddresses
Why it's wrong here
proxyAddresses controls secondary SMTP addresses and mail routing, not the primary cloud UPN. Modifying it will not change the userPrincipalName in Microsoft Entra ID. While proxyAddresses can influence mail flow, it is unrelated to the sign-in address used for cloud authentication. Therefore, it does not achieve the goal of altering the cloud UPN.
- ✗
mail
Why it's wrong here
The mail attribute is used for email addressing and is synchronized to Microsoft Entra ID as the user's email address, but it does not determine the sign-in userPrincipalName. Changing it will not alter the cloud UPN. Thus, it is not the correct attribute to modify for changing the cloud sign-in address.
- ✓
userPrincipalName
Why this is correct
The userPrincipalName attribute in the on-premises directory is synchronized to Microsoft Entra ID as the user's sign-in name, provided the domain is verified. Changing it to match the desired cloud UPN (e.g., jdoe@corp.com) will update the cloud userPrincipalName after synchronization. This is the correct attribute to modify to control the cloud sign-in address.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.