Courseiva

CCNA Azure Apps And Attacks Questions

11 questions · Azure Apps And Attacks topic · All types, answers revealed

1
MCQhard

An attacker has gained access to an Azure VM and wants to escalate privileges by abusing the VM's managed identity. The managed identity has the 'Contributor' role on the subscription. Which of the following actions would allow the attacker to add a new user to an Azure AD group that has 'Global Administrator' role?

A.The attacker cannot perform this action because the 'Contributor' role does not grant permissions to modify Azure AD groups.
B.Use the managed identity to assign the 'User Access Administrator' role to itself, then add the user to the group.
C.Use the managed identity to call the Microsoft Graph API and add the user to the group.
D.Use the managed identity to create a new service principal with 'Global Administrator' role, then use it to add the user.
AnswerA

The 'Contributor' role on a subscription allows management of Azure resources but not Azure AD objects. Adding a user to an Azure AD group requires Azure AD permissions, which the managed identity lacks. Therefore, the attacker cannot perform this action with the given role.

Why this answer

Azure RBAC roles like 'Contributor' grant permissions to manage Azure resources, not Azure AD objects. Adding a user to an Azure AD group is an Azure AD operation that requires directory permissions. The managed identity does not have these permissions, so the attacker cannot escalate privileges this way.

The attacker would need to find a different path, such as compromising an account with Azure AD admin roles.

Exam trap

The trap here is conflating Azure RBAC roles with Azure AD roles, assuming that 'Contributor' allows modification of Azure AD groups, which it does not.

2
MCQeasy

A penetration tester is assessing an Azure environment and discovers a function app with an HTTP trigger that does not require authentication. The function app has a system-assigned managed identity with Contributor role on the subscription. What is the most immediate risk?

A.The function app's source code can be downloaded, revealing secrets and connection strings.
B.The function app's logs can be accessed, revealing sensitive information.
C.The function app can be used to send emails or messages, leading to spam or phishing.
D.The function app can be used to perform actions on any resource in the subscription, potentially leading to full subscription compromise.
AnswerD

With Contributor role on the subscription, the managed identity can create, modify, or delete any resource. Since the HTTP trigger is unauthenticated, anyone can invoke the function and have it perform actions using that identity. This could allow an attacker to escalate privileges, deploy malicious resources, or delete critical assets.

Why this answer

The unauthenticated HTTP trigger allows anyone to invoke the function. If the function's managed identity has Contributor role on the subscription, an attacker can use the function to execute actions with that identity, effectively gaining Contributor-level access to the entire subscription. This is a severe privilege escalation.

Exam trap

The trap here is focusing on data exposure like source code or logs instead of the direct privilege escalation enabled by the managed identity's high permissions.

3
MCQmedium

When conducting a penetration test on an Azure App Service, you discover an 'environment.js' file in the public directory containing a 'CLIENT_ID'. What is the risk associated with this finding?

A.The attacker can use the Client ID to authenticate as the application.
B.The attacker can use the Client ID to construct a tailored consent-phishing URL.
C.The attacker can use the Client ID to reset the application's password.
D.The attacker can use the Client ID to bypass MFA for the application.
AnswerB

The Client ID is a required parameter for the OAuth2 authorization URL. By knowing the ID, an attacker can build a custom URL that directs users to the Microsoft identity platform to grant permissions to the application, making the phishing attempt look more legitimate to the target user.

Why this answer

Client IDs are public and not secrets in themselves. However, exposing them can reveal the application's configuration and identifier, which an attacker can then use to craft malicious authorization requests. If the application is misconfigured to allow unauthorized consent or has other vulnerabilities, the Client ID acts as the starting point for a targeted phishing or consent-based attack against the organization's users.

Exam trap

Candidates often mistake a Client ID for a sensitive secret like a Client Secret or Certificate. Consequently, they overestimate the immediate danger of an 'environment.js' file exposure.

4
MCQmedium

Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What security implication does this setting present for enterprise applications?

A.Only users explicitly assigned via Azure AD Enterprise Applications can authenticate and access the application.
B.Any user in the Azure AD tenant can authenticate to the application and obtain access tokens without prior assignment.
C.The application is prohibited from utilizing OAuth 2.0 authorization code flows and must rely exclusively on client credentials.
D.Global administrators must manually approve every single sign-in attempt generated by standard users in the tenant.
AnswerB

Setting this property to false bypasses the user assignment requirement entirely. This default setting means every member of the directory is authorized to log in, which can be dangerous if the application contains sensitive internal functionality.

Why this answer

The 'appRoleAssignmentRequired' property dictates whether users must be explicitly assigned to an enterprise application before they can successfully authenticate. When set to false, any user within the directory can acquire tokens for the application, expanding the attack surface and potential exposure.

Exam trap

Candidates often assume that setting 'appRoleAssignmentRequired' to false restricts access to administrators only, when in reality it opens access to all tenant users.

5
MCQmedium

An attacker is performing reconnaissance on an Azure AD tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?

A.External collaboration settings for Guest user access restrictions.
B.Conditional Access policy for guest users.
C.The 'Enable Global Reader' role for guests.
D.The 'AppRoleAssignmentRequired' property of the tenant.
AnswerA

This setting in the Azure AD 'External Identities' configuration explicitly controls the visibility of guest users. By setting this to 'Limited access', guests can only see their own profile, which prevents them from enumerating other users, groups, or sensitive directory information.

Why this answer

By default, Azure AD allows guest users to see other users and groups in the directory. This is a common reconnaissance vector for attackers to map the organization's structure. Restricting this access is a critical step in hardening the tenant, ensuring that guest identities have limited visibility into the internal organizational structure during an initial compromise.

Exam trap

Candidates frequently look for 'Conditional Access' policies or 'Role-Based Access Control' settings. They miss the specific 'External collaboration settings' menu, which controls global directory visibility for guest users.

6
MCQmedium

During an Azure penetration test, you discover an App Registration with an expired client secret that still has active refresh tokens issued prior to expiration. The application holds high-privilege directory roles. How do these leaked refresh tokens behave regarding Azure AD security boundaries?

A.The refresh tokens are instantly invalidated the moment the underlying client secret expires or is rotated in the Azure portal.
B.The refresh tokens continue to function and can be exchanged for new access tokens until the refresh token's own lifetime expires or it is explicitly revoked.
C.The refresh tokens automatically convert into guest user sessions with restricted privileges to mitigate potential compromise of internal directory roles.
D.The refresh tokens fail immediately because Azure AD enforces continuous access evaluation for all service principal API interactions.
AnswerB

Azure AD architecture decouples token lifespans from credential lifespans once the session is established. A valid refresh token permits continuous generation of short-lived access tokens, enabling persistence even if the administrator deletes or rotates the original application secret.

Why this answer

Active refresh tokens bypass initial credential checks until they expire or are explicitly revoked, allowing prolonged unauthorized access to enterprise resources. Understanding this persistence mechanism is critical for penetration testers assessing token lifetime policies and identifying stealthy persistence vectors within enterprise environments.

Exam trap

Candidates often assume that rolling over or expiring a client secret immediately invalidates all previously issued OAuth tokens, forgetting that issued refresh tokens remain fully functional until their absolute lifetime is reached.

7
MCQhard

An attacker has obtained a refresh token for an Azure AD application with the 'Mail.Read' delegated permission. The token was issued to a user who has since had their password reset and all refresh tokens revoked. The attacker attempts to use the refresh token to obtain a new access token. What is the expected outcome?

A.The refresh token will still work because it is not invalidated by password reset or token revocation.
B.The refresh token will fail because it was revoked, and the attacker must re-authenticate to obtain a new one.
C.The refresh token will work only if the application has the 'offline_access' permission.
D.The refresh token will fail because it is bound to the user's password hash, which changed.
AnswerB

When a password is reset or tokens are revoked, Azure AD invalidates all refresh tokens for that user. The attacker's refresh token is therefore useless. To regain access, the attacker would need to compromise the account again and perform a new authentication flow.

Why this answer

Azure AD invalidates all refresh tokens for a user when their password is reset or when tokens are explicitly revoked. This is a security measure to prevent token replay after credential compromise. The attacker's refresh token is therefore invalid, and any attempt to redeem it will result in an error.

The attacker would need to re-authenticate with valid credentials to obtain new tokens.

Exam trap

The trap here is believing that refresh tokens survive password resets or that they are tied to the password hash, when in fact they are simply revoked en masse.

8
MCQhard

An attacker has compromised an Azure App Service and obtained the application's managed identity token. They want to use it to access an Azure SQL Database. The managed identity has been granted access to the SQL server. Which of the following is the correct way to authenticate to the SQL Database using the managed identity token?

A.Use the token to call the Azure SQL REST API to execute queries.
B.Use the token as the password in a SQL connection string with 'Authentication=Active Directory Password'.
C.Use the token in the 'Access Token' property of a SqlConnection object with 'Authentication=Active Directory Access Token'.
D.Use the token to authenticate to the Azure SQL server's master database and then impersonate a user.
AnswerC

Azure SQL supports Azure AD access token authentication via the 'Access Token' property in SqlConnection. The token must be obtained for the resource https://database.windows.net/. This method allows the managed identity to authenticate without a password. It is the correct approach to leverage the token for SQL access.

Why this answer

The correct method is to use the managed identity's access token directly in the SqlConnection object with 'Authentication=Active Directory Access Token'. The token must be scoped to https://database.windows.net/. This allows the application to authenticate to Azure SQL using the managed identity, leveraging its assigned permissions.

Exam trap

The trap here is assuming that the token can be used as a password in a connection string, which is a common misconception but not how Azure AD token authentication works for SQL.

9
MCQmedium

During an Azure penetration test, you gain access to a Linux VM in a subnet that has a user-defined route forcing all traffic through a Network Virtual Appliance (NVA). You want to reach the Azure Instance Metadata Service (IMDS) to steal managed identity tokens. Which of the following best describes how you can access IMDS from this VM?

A.IMDS is reachable at 168.63.129.16, but the user-defined route will block access, requiring you to disable the route first.
B.IMDS is reachable at 169.254.169.254, and the user-defined route does not affect this link-local address, so you can query it directly from the VM.
C.IMDS is reachable at 169.254.169.254, but the user-defined route will redirect the request to the NVA, so you must use a proxy to reach it.
D.IMDS is reachable only from within the Azure portal, so you must use the Azure CLI from your attacker workstation to query it.
AnswerB

This is correct because IMDS uses the link-local address 169.254.169.254, which is handled by the Azure platform and bypasses user-defined routes and NVAs. From the compromised VM, you can directly query IMDS to obtain managed identity tokens without any network appliance interfering, making it a reliable credential theft vector.

Why this answer

The Azure Instance Metadata Service is a REST endpoint at 169.254.169.254 that provides metadata and managed identity tokens to VMs. Because it uses a link-local address, traffic to it is intercepted by the Azure platform and is not subject to user-defined routes, NVAs, or network security groups. An attacker on a compromised VM can directly query IMDS to obtain access tokens for any managed identity assigned to that VM, enabling lateral movement or privilege escalation.

Exam trap

The trap here is assuming that user-defined routes or NVAs can intercept or block IMDS traffic, when in fact link-local traffic to 169.254.169.254 bypasses such routing.

10
MCQmedium

Which of the following describes the risk of 'App Role' over-assignment in Azure AD?

A.It increases the likelihood of a brute-force attack on the tenant.
B.It allows an attacker to escalate privileges if a user account is compromised.
C.It automatically bypasses the need for Multi-Factor Authentication.
D.It prevents the application from using external OAuth2 scopes.
AnswerB

If a user is assigned an administrative app role, any attacker who compromises that user's account gains those high-level permissions within the application. This makes over-assignment a direct path to privilege escalation, allowing attackers to access features or data that the average user should never touch.

Why this answer

App Roles define what a user or application can do within a specific application context. If an administrator assigns 'Admin' roles to too many users, an attacker compromising any one of those users gains elevated privileges within that application. This lateral movement risk emphasizes the need to assign roles to groups rather than individual users and to audit role assignments periodically to ensure least privilege.

Exam trap

Candidates frequently confuse Azure AD global roles with application-specific roles, missing how localized app role over-assignment still permits significant lateral movement.

11
MCQhard

A penetration tester is reviewing an Azure Logic App that uses a managed identity to access an Azure SQL Database. The tester finds that the Logic App's workflow definition is stored in a storage account that is publicly accessible. The workflow includes a step that executes a stored procedure with parameters. Which of the following is the most significant risk of this misconfiguration?

A.An attacker can modify the workflow to exfiltrate data from the SQL Database using the managed identity.
B.An attacker can disable the managed identity by deleting the Logic App.
C.An attacker can use the managed identity to authenticate to Azure AD and create new users.
D.An attacker can retrieve the managed identity's client secret from the workflow definition.
AnswerA

If the workflow definition is publicly accessible and can be modified, an attacker could alter the workflow to include malicious actions, such as querying sensitive data and sending it to an external endpoint. The managed identity would execute these actions with its permissions, leading to data exfiltration. This is a severe risk because the managed identity likely has access to the database, and the attacker can leverage that without needing credentials.

Why this answer

The most significant risk is that an attacker can modify the publicly accessible workflow definition to perform malicious actions using the managed identity's privileges. Since the managed identity can access the SQL Database, the attacker could alter the workflow to extract data and send it externally. This highlights the importance of securing Logic App definitions and limiting access to storage accounts.

Exam trap

The trap here is assuming that the managed identity's secret is exposed or that the attacker can delete resources, rather than focusing on the ability to modify the workflow to abuse the identity's permissions.

Ready to test yourself?

Try a timed practice session using only Azure Apps And Attacks questions.