GPEN Azure AD Integration Practice Question
Which of the following describes the risk of 'Guest User' accounts in an Microsoft Entra ID integration scenario?
⚠ Common exam trap
Candidates often assume that guest accounts are harmless because they have 'limited' access. They fail to realize that the default directory enumeration permissions can leak sensitive information about the entire organization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Guest users can potentially enumerate directory objects unless restricted.
Guest accounts in Microsoft Entra ID often have default permissions that allow them to enumerate directory objects. If these guests are not properly scoped using 'External Collaboration Settings', an attacker can use a compromised guest account to map the internal organizational structure, identify high-value targets, and find misconfigured applications. This reconnaissance is often the first step in a broader, more successful targeted attack against the internal environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Guest users are automatically granted Global Administrator privileges.
Why it's wrong here
Guest users do not receive administrative privileges by default. They are assigned the 'Guest' role, which has restricted permissions. The risk arises from the default ability to enumerate directory objects, not from excessive administrative permissions being granted automatically upon the creation of the guest user.
- ✗
Guest accounts can only be created by the Global Administrator.
Why it's wrong here
Microsoft Entra ID allows for delegated invitation of guest users. By default, many users within the organization may have the ability to invite external guests. If this is not restricted, it leads to an unmanaged expansion of the identity footprint, creating visibility and security governance challenges for administrators.
- ✓
Guest users can potentially enumerate directory objects unless restricted.
Why this is correct
By default, guest users can read directory information, including the list of users, groups, and applications. Restricting these permissions via the 'External Collaboration Settings' in Microsoft Entra ID is a mandatory hardening step to ensure that external entities cannot perform reconnaissance on the internal directory structure.
- ✗
Guest users are exempt from Conditional Access policies.
Why it's wrong here
Conditional Access policies can and should be applied to guest users. Administrators have the option to include or exclude guest users from these policies. Failing to include them in security policies is a configuration choice, not a fundamental property of the guest user account type.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.