Courseiva
Azure AD Integration →mediumMultiple Choice

GPEN Azure AD Integration Practice Question

Why is 'Password Writeback' considered a significant security risk in hybrid identity integrations?

⚠ Common exam trap

Test-takers frequently confuse Password Writeback with single sign-on or directory synchronization benefits, overlooking the critical bidirectional security risk of cloud-to-on-premises escalation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It allows cloud-based compromise to escalate into the on-premises domain.

Password Writeback enables the cloud to update passwords on-premises. While convenient, it creates a bidirectional path. If an attacker gains control of a cloud-based administrator account, they can reset the password of any on-premises user, including sensitive accounts. This effectively elevates the cloud's influence over the on-premises environment, turning a cloud-only compromise into a full-scale domain-wide security disaster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It stores plaintext passwords on the Microsoft Entra Connect server.

    Why it's wrong here

    Password writeback does not store passwords in plaintext. The process uses secure, encrypted channels to communicate back to the on-premises environment. While the risk is high, it stems from the ability to change passwords, not from the exposure of plaintext credentials at rest on the server.

  • ✓

    It allows cloud-based compromise to escalate into the on-premises domain.

    Why this is correct

    By allowing the cloud to set on-premises passwords, the trust boundary is reversed. An attacker who compromises a high-privileged account in Microsoft Entra ID can use the writeback feature to reset passwords for Domain Admins or other sensitive accounts, granting them full control over the on-premises infrastructure.

  • ✗

    It requires the on-premises firewall to allow inbound connections from the internet.

    Why it's wrong here

    Password writeback, like other Microsoft Entra Connect features, functions over an outbound connection initiated by the agent. No inbound ports need to be opened on the on-premises firewall, maintaining the network perimeter. The security risk is purely related to the identity trust model, not network exposure.

  • ✗

    It automatically disables the on-premises password policy.

    Why it's wrong here

    Password writeback enforces the on-premises password policy during the reset process. It does not disable or bypass the local domain's complexity or history requirements. The risk is not in policy bypass, but in the unauthorized use of the writeback feature to perform account takeovers.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.