Courseiva

GPEN · topic practice

Azure AD Integration practice questions

This domain covers attacking and defending hybrid identity in Microsoft Entra ID (Azure AD), including Azure AD Connect synchronization, Pass-Through Authentication, AD FS federation, and token/session abuse. Questions test whether you can trace an on-premises compromise to cloud privilege escalation, choose valid mitigations, and maintain persistence using real Entra ID and Windows identity features.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Azure AD Integration

What the exam tests

What to know about Azure AD Integration

You must map an on-premises identity compromise to its Entra ID impact by identifying the sync method, sourceAnchor attribute, and authentication path. The most important thing is correctly determining whether credentials, tokens, or federation certificates grant cloud access and persistence.

Azure AD Connect sync methods: password hash sync, Pass-Through Authentication, and federation with AD FS

ms-DS-ConsistencyGuid and ImmutableID mapping for sourceAnchor and cloud identity correlation

Password spray mitigation using Entra ID Password Protection, smart lockout, and Conditional Access

AD FS token signing certificate theft, Golden SAML, and primary refresh token abuse for persistence

Watch out for

Common Azure AD Integration exam traps

  • ▸Assuming any synchronized on-premises user can directly modify cloud-only attributes without directory role or writeback permissions
  • ▸Confusing Pass-Through Authentication with password hash synchronization when assessing credential theft and spray impact
  • ▸Treating AD FS as equivalent to cloud authentication and missing token-signing certificate or Golden SAML persistence paths

Practice set

Azure AD Integration questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full AD Integration explanation →

An organization uses Azure AD Connect to synchronize on-premises identities. A security auditor discovers that password hash synchronization is enabled. What is the primary security implication of this feature in a hybrid environment?

Which TWO of the following configurations are considered best practices to secure the Azure AD Connect synchronization server?

Question 3mediummultiple choice
Read the full AD Integration explanation →

Refer to the exhibit. What is the primary security risk associated with the current configuration of the Conditional Access policy?

Exhibit

{"Policy": "ConditionalAccess", "Assignment": {"Users": "All", "Apps": "All"}, "Control": "Grant", "Status": "Enabled", "Exclusions": ["Global_Admin_Break_Glass_Account"]}
Question 4mediummultiple choice
Read the full AD Integration explanation →

What is the security significance of the 'Domain Admin' group synchronization from on-premises to Azure AD?

Refer to the exhibit. What is the most likely cause of this authentication failure?

Exhibit

Sign-in Error: 50126
Description: Invalid username or password.
Additional Details: Conditional Access policy 'Block_Legacy_Auth' triggered.

Which TWO of the following are potential indicators of an Azure AD identity-based attack?

Question 7mediummultiple choice
Read the full AD Integration explanation →

During an internal penetration test against an organization utilizing hybrid identity, you compromise an on-premises Active Directory service account with DCSync privileges. You want to leverage this access to establish persistent access to Microsoft Entra ID (formerly Azure AD) without triggering standard on-premises password change alerts. Which method provides the most effective persistence mechanism leveraging hybrid synchronization mechanics?

You have gained execution on a workstation where a global administrator previously ran Azure CLI commands, leaving residual authentication tokens in the local user profile cache. You locate the refresh token files. What is the primary operational security limitation an attacker faces when attempting to replay these stolen Microsoft Entra ID refresh tokens from an external infrastructure IP address?

During a penetration test of a Microsoft Entra ID environment, you compromise a user account that has the 'Application Administrator' role. You aim to escalate privileges to Global Administrator by abusing this role. Which of the following actions would BEST achieve this objective?

You are assessing a Microsoft Entra ID environment integrated with on-premises Active Directory. You have obtained credentials for a user who is a member of the 'Azure AD Joined Device Local Administrator' role. Which TWO of the following actions can this user perform that could aid in further compromising the environment? (Choose two.)

Question 11hardmultiple choice
Read the full AD Integration explanation →

You have obtained a refresh token for a user via a compromised device in a Microsoft Entra ID integrated environment. You want to maintain persistent access to Microsoft Graph even after the user's password is changed. Which of the following actions should you take?

Question 12mediummultiple choice
Read the full AD Integration explanation →

You are conducting a penetration test against a Microsoft Entra ID tenant that has Seamless Single Sign-On (SSO) enabled with Azure AD Connect. You have obtained a valid domain user's cleartext credentials. You need to obtain a Kerberos service ticket for the Azure AD Connect computer account to abuse the Seamless SSO feature. Which tool and command should you use?

Question 13mediummultiple choice
Read the full AD Integration explanation →

During a penetration test of a Microsoft Entra ID environment, you discover that a custom domain (e.g., corp.com) is not verified in the tenant. However, an on-premises user has a userPrincipalName that uses this unverified domain. What is the effect on the synchronized cloud userPrincipalName for this user?

Question 14easymultiple choice
Read the full AD Integration explanation →

A penetration tester is assessing a Microsoft Entra ID environment that uses Password Hash Synchronization (PHS) with Azure AD Connect. The tester has obtained the hash of a user's password from the on-premises Active Directory. Which attack can the tester perform to authenticate as the user in Entra ID without cracking the hash?

During a penetration test of a Microsoft Entra ID environment integrated with on-premises Active Directory, you have compromised a workstation and extracted credentials of a user who is a member of the 'Azure AD Joined Device Local Administrator' role. You now want to escalate privileges to Global Administrator. Which TWO of the following methods could you use to achieve this? (Choose two.)

Question 16easymultiple choice
Read the full AD Integration explanation →

During a penetration test of a Microsoft Entra ID environment, you discover that the tenant has self-service password reset (SSPR) enabled for all users. You have compromised a standard user account. Which of the following methods could you use to attempt to reset the password of a more privileged user via SSPR?

Question 17mediummultiple choice
Read the full AD Integration explanation →

You are performing a penetration test on a Microsoft Entra ID tenant that uses federated authentication with Active Directory Federation Services (AD FS). You have compromised a user account in the on-premises domain. Which of the following actions would allow you to authenticate as a different user in the cloud without knowing their password?

Question 18mediummultiple choice
Read the full AD Integration explanation →

During an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?

Question 19hardmultiple choice
Read the full AD Integration explanation →

When analyzing a hybrid identity environment, you notice the use of 'Seamless Single Sign-On'. What is the potential impact if the 'AZUREADSSOACC' computer object in the on-premises Active Directory is compromised?

Question 20mediummultiple choice
Read the full AD Integration explanation →

Which of the following describes the risk of 'Guest User' accounts in an Azure AD integration scenario?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Azure AD Integration sessions

Start a Azure AD Integration only practice session

Every question in these sessions is drawn from the Azure AD Integration domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Azure AD Integration?
You must map an on-premises identity compromise to its Entra ID impact by identifying the sync method, sourceAnchor attribute, and authentication path. The most important thing is correctly determining whether credentials, tokens, or federation certificates grant cloud access and persistence.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Azure AD Integration questions in a focused session?
Yes — the session launcher on this page draws every question from the Azure AD Integration domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.