Courseiva
Azure AD Integration →mediumMultiple Choice

GPEN Azure AD Integration Practice Question

You are conducting an internal penetration test for a client that uses Microsoft Entra ID (Azure AD) with on-premises Active Directory. You have obtained a low-privileged domain user's credentials. You want to enumerate Entra ID users and groups without triggering sign-in logs on the compromised user. Which of the following techniques would be MOST effective for this goal?

⚠ Common exam trap

The trap here is assuming that any cloud enumeration requires authenticating to Entra ID, overlooking that synchronized on-premises objects can be enumerated locally without generating cloud logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Query the on-premises Active Directory for objects synchronized to Entra ID using the user's existing domain access.

The objective is to enumerate Entra ID objects without creating sign-in logs on the compromised user. Querying on-premises Active Directory leverages the existing domain session and does not generate cloud authentication events. This method can reveal synchronized users and groups, providing valuable intelligence while maintaining operational security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authenticate to Microsoft Graph with the compromised user's credentials and enumerate users and groups.

    Why it's wrong here

    Authenticating to Microsoft Graph with the compromised user's credentials would generate sign-in logs in Entra ID, directly contradicting the requirement to avoid triggering sign-in logs on that user. While it is a valid enumeration method, it fails the stealth objective of the scenario.

  • ✗

    Use the Microsoft Entra Connect synchronization account to query the Microsoft Graph API.

    Why it's wrong here

    The Microsoft Entra Connect synchronization account is a high-privilege service account that typically has directory synchronization permissions. Using it would generate high-severity alerts and is not a low-privileged enumeration technique. Moreover, obtaining its credentials from a low-privileged user is unlikely, and its use would not be stealthy.

  • ✗

    Use the Microsoft Entra admin center with the compromised user's credentials to browse users and groups.

    Why it's wrong here

    Accessing the Microsoft Entra admin center requires interactive sign-in and will generate Entra ID sign-in logs for the compromised user. Additionally, a low-privileged user typically lacks permissions to read all users and groups, making this both noisy and ineffective for enumeration.

  • ✓

    Query the on-premises Active Directory for objects synchronized to Entra ID using the user's existing domain access.

    Why this is correct

    Querying on-premises AD uses the user's existing domain authentication, which does not create Entra ID sign-in logs. Since synchronized objects exist in both directories, enumerating on-premises AD can reveal a significant portion of Entra ID users and groups without touching the cloud identity provider, achieving stealth.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.