Courseiva
Azure AD Integration →hardMultiple Select

GPEN Azure AD Integration Practice Question

Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Microsoft Entra ID environment?

⚠ Common exam trap

Candidates often select controls like self-service password reset or password complexity rules, which fail to specifically address password spray attacks targeting multiple accounts with common passwords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce Multi-Factor Authentication for all users.

Password spray attacks target common passwords across many accounts. Protecting against this requires a layered approach: enforcing MFA to render weak passwords useless, blocking legacy authentication to prevent bypasses, and utilizing identity protection to detect anomalous logins. These controls are essential for modernizing identity security and protecting against high-volume, low-effort credential attacks that plague hybrid environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enforce Multi-Factor Authentication for all users.

    Why this is correct

    MFA is the most effective control against password spraying. Even if an attacker guesses the password, the secondary factor prevents them from gaining access. It neutralizes the utility of the guessed credential, forcing the attacker to find another way to circumvent the authentication process entirely.

  • ✓

    Disable all legacy authentication protocols.

    Why this is correct

    Legacy protocols such as POP3, IMAP, and SMTP often do not support modern MFA. Attackers use these protocols to bypass Conditional Access policies entirely. Disabling legacy auth forces all authentication attempts through modern auth flows, where MFA and other conditional controls are enforced and effective.

  • ✓

    Implement Identity Protection to detect and block risky sign-ins.

    Why this is correct

    Microsoft Entra ID Protection uses machine learning to identify sign-in risks, such as impossible travel or known malicious IP addresses. By integrating this with Conditional Access, the system can automatically block sign-ins from suspicious sources, effectively stopping spray attacks that originate from common botnet infrastructure.

  • ✗

    Increase the minimum password length to 50 characters.

    Why it's wrong here

    While increasing complexity and length improves resilience against brute-force attacks, it does not stop password spraying, which relies on common, widely used passwords. Users will often choose simple phrases that meet length requirements but are still easily guessable, rendering this control ineffective for this specific threat vector.

  • ✗

    Require all users to use the same password for both on-premises and cloud.

    Why it's wrong here

    Enforcing the same password across environments is a security anti-pattern that increases the impact of a credential compromise. If one environment is breached, the attacker automatically gains access to both. This configuration does nothing to mitigate password spraying and significantly degrades the overall security posture.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.