Courseiva

GPEN · topic practice

Azure Apps and Attacks practice questions

This domain covers attacking and auditing Microsoft Entra ID application identities and Azure compute resources. Candidates query Microsoft Graph, inspect App Registrations and service principals, abuse managed identities, and trace how Logic Apps, App Services, and storage accounts expose tokens or workflow definitions during an engagement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Azure Apps and Attacks

What the exam tests

What to know about Azure Apps and Attacks

Be able to enumerate Entra ID app identities with Microsoft Graph, assess credential and token validity, and pivot from a compromised Azure workload using its managed identity. The critical point is matching token audience and permissions to the target resource before attempting access.

Querying Microsoft Graph for service principals, appRoleAssignmentRequired, and app role assignments

Analyzing App Registration credentials, expired client secrets, and still-valid refresh tokens

Abusing managed identity tokens from App Service or Logic App to reach Azure SQL Database

Reviewing publicly accessible storage accounts holding Logic App workflow definitions

Watch out for

Common Azure Apps and Attacks exam traps

  • ▸Assuming an expired client secret invalidates existing refresh tokens; refresh tokens can remain usable after secret expiry.
  • ▸Treating appRoleAssignmentRequired=false as harmless; it can allow users or groups to access the app without explicit assignment.
  • ▸Forgetting that managed identity tokens are audience-scoped, so a token for one resource cannot be replayed against Azure SQL or Graph.

Practice set

Azure Apps and Attacks questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Apps and Attacks explanation →

An attacker has compromised an Azure AD application with the 'User.Read.All' delegated permission. They seek to elevate privileges by abusing the 'onBehalfOf' flow. What is the primary requirement for this attack to succeed?

Which TWO of the following actions are necessary for an attacker to perform a 'Consent Phishing' attack against an Azure AD tenant?

Question 3mediummultiple choice
Read the full Apps and Attacks explanation →

Refer to the exhibit. Which security implication does this application configuration have regarding access control?

Exhibit

{
  "AppRoleAssignmentRequired": true,
  "RequiredResourceAccess": [
    {
      "ResourceAppId": "00000003-0000-0000-c000-000000000000",
      "ResourceAccess": [
        { "Id": "e1fe6dd8-ba31-4d61-89e7-88639da4683d", "Type": "Scope" }
      ]
    }
  ]
}
Question 4mediummultiple choice
Read the full Apps and Attacks explanation →

An attacker finds an Azure Function with an improperly secured HTTP trigger. They want to enumerate the environment variables of the function. Which path is the most likely target for this enumeration?

A developer has assigned a User-Assigned Managed Identity to an Azure App Service. The attacker successfully gains local file access to the App Service instance. How can they obtain an OAuth token for the Azure Resource Manager (ARM) API?

Which THREE of the following are common misconfigurations in Azure AD application registrations that lead to potential privilege escalation?

Refer to the exhibit. An Azure storage account has this policy applied to its blob container. What is the most significant security impact of this configuration?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "*",
      "Resource": "*"
    }
  ]
}
Question 8mediummultiple choice
Read the full Apps and Attacks explanation →

An attacker has compromised an Azure AD user account with MFA enabled. What is the most likely technique they will use to maintain access without constantly triggering MFA?

Which TWO of the following are valid methods to identify Azure AD applications that have excessive permissions in a production environment?

An attacker has gained access to an Azure VM with a System-Assigned Managed Identity. They find the IMDS endpoint is accessible. What prevents them from simply requesting a token for the Microsoft Graph API?

An attacker compromises a web application hosted in Azure App Service that utilizes a system-assigned managed identity to connect to an Azure SQL Database. How can the attacker pivot from the compromised web app to extract secrets or access backend resources?

An attacker has compromised an Azure App Service that uses a system-assigned managed identity. They want to use the managed identity to access an Azure Key Vault. Which two of the following steps are required to obtain and use the managed identity token from within the App Service? (Choose two.)

Question 13mediummultiple choice
Read the full Apps and Attacks explanation →

During an Azure penetration test, you obtain an access token for a managed identity attached to an Azure VM. You want to use this token to access an Azure Key Vault that stores secrets. Which Azure CLI command correctly attempts to retrieve a secret from the Key Vault using the managed identity's token?

Question 14mediummultiple choice
Read the full Apps and Attacks explanation →

A penetration tester is assessing an Azure subscription where a web application is deployed to Azure App Service. The tester discovers that the App Service's system-assigned managed identity has been granted the 'Storage Blob Data Contributor' role on a storage account. The tester can execute arbitrary code on the App Service via a web shell. What is the most direct method to exfiltrate data from the storage account?

A penetration tester is reviewing an Azure App Service configuration and notices that the application has a managed identity enabled. The tester wants to leverage this identity to access an Azure SQL Database. Which of the following is the most appropriate way to authenticate to the database using the managed identity?

Question 16mediummultiple choice
Read the full Apps and Attacks explanation →

During a penetration test of an Azure environment, you obtain a low-privileged user account. You discover the user can read the properties of a managed identity attached to an Azure VM. You want to leverage this managed identity to access an Azure Key Vault that stores secrets. Which of the following steps is the most direct way to obtain an access token for the managed identity?

A penetration tester is assessing an Azure App Service web application. The application uses an App Service Environment (ASE) and has a system-assigned managed identity. The tester discovers that the application has an SSRF vulnerability that allows making HTTP requests to internal endpoints. Which of the following internal endpoints could the tester target to retrieve an access token for the managed identity?

An attacker has gained access to an Azure AD application with the 'Directory.Read.All' permission. They want to escalate privileges by adding a new credential to a highly privileged service principal. Which two of the following steps are necessary to achieve this? (Choose two.)

Question 19mediummultiple choice
Read the full Apps and Attacks explanation →

An attacker is performing reconnaissance on an Azure AD tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?

Question 20mediummultiple choice
Read the full Apps and Attacks explanation →

When conducting a penetration test on an Azure App Service, you discover an 'environment.js' file in the public directory containing a 'CLIENT_ID'. What is the risk associated with this finding?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Azure Apps and Attacks sessions

Start a Azure Apps and Attacks only practice session

Every question in these sessions is drawn from the Azure Apps and Attacks domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Azure Apps and Attacks?
Be able to enumerate Entra ID app identities with Microsoft Graph, assess credential and token validity, and pivot from a compromised Azure workload using its managed identity. The critical point is matching token audience and permissions to the target resource before attempting access.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Azure Apps and Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Azure Apps and Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.