▸case-22 Write an internal email announcement to all employees introducing mandatory Microsoft Authenticator app registration for company mobile phones, including setup steps for scanning the QR code in the security info portal. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 Our IT compliance team needs to configure Entra ID Smart Lockout settings to prevent automated brute-force password spraying against user accounts. Recommend standard threshold values for lockout duration and failed login count. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 Our security team is conducting an audit on our enterprise authentication defenses against reverse-proxy phishing kits. Can you outline a comprehensive guide detailing how these attacks operate, key detection indicators to log, and specific defensive configurations needed across identity providers and web proxies? Deliver this as a structured assessment document with an overview, technical phases, and validation criteria. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 Create an identity access governance standard detailing how enterprise identity providers should handle requests originating from anonymizing networks like Tor or unverified proxy nodes during authentication attempts. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 Threat actors who gain session access via EvilProxy often attempt to maintain persistent access without relying on the stolen cookie. What Azure AD application management event should trigger immediate SOC investigation? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 We need to validate our newly deployed SIEM detection rules for AiTM session hijacking. Outline a validation test strategy that proves our Conditional Access and SIEM controls successfully detect or block session token reuse. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 We are hardening privileged Entra ID administrator accounts against proxy-based MFA bypass. Draft an administrative directive outlining which legacy or weak authentication methods must be completely disabled for admins and why standard MFA fallback options fail. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 Our threat intelligence team is profiling modern PhaaS frameworks to tune our edge defenses. Compare Tycoon 2FA, EvilProxy, and Evilginx in terms of their targeted platforms, primary evasion techniques, and underlying architecture. Summarize these in a structured reference guide. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 After a user enters credentials on a reverse-proxy site and completes MFA, what specific post-authentication telemetry events in Microsoft 365 indicate an attacker has taken over the account session and is preparing for business email compromise? List the primary initial actions to monitor. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 How should identity risk scores generated during an ongoing session be utilized within Entra ID to mitigate compromised sessions in progress? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 During our Entra ID security review, developers suggested blocking non-US IP addresses as the main safeguard against session cookie theft from phishing sites. Write a policy design document highlighting why IP fencing alone fails and which specific Entra ID Conditional Access controls must be enabled to mitigate token replay and revoke active sessions in real time. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 We manage a hybrid IdP environment running both Okta and Microsoft Entra ID. We need to deploy IdP-native risk engines specifically designed to detect adversary-in-the-middle proxy requests at the IdP edge. Recommend the specific built-in products/features for both platforms. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 We are upgrading our MFA enforcement in Microsoft Entra ID for executive accounts to prevent session hijacking via reverse proxies. Our team believes Push Notifications with Number Matching is sufficient to stop adversary-in-the-middle proxy kits. Please provide an authentication architecture recommendation detailing why push notifications fail and what specific credential standard stops origin domain spoofing. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 Once an attacker hijacks an M365 session via Sneaky 2FA, how does the attacker typically leverage the compromised mailbox to expand the attack internally, and what specific email sending pattern should be monitored? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 We are configuring custom detection rules in Microsoft Sentinel for session cookie theft following phishing sign-ins. Standard travel anomalies are triggering too many false positives over 24-hour windows. Provide precise detection logic criteria focusing on immediate session reuse anomalies and post-auth infrastructure patterns. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 Our threat research team encountered mentions of Sneaky 2FA and NakedPages in recent incident reports. Detail the key characteristics, primary targets, and evasion capabilities of these two PhaaS kits. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 When designing a zero-trust authentication framework to resist AiTM attacks, explain why certificate-based authentication and FIDO2 security keys protect against reverse proxies while standard passwords with push notifications fail. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 We are configuring SPF, DKIM, and DMARC DNS records for our corporate domain company.com to prevent domain spoofing in outgoing marketing emails. Provide a standard DMARC policy record formatted for DNS with a quarantine policy and aggregate reporting email at dmarc@company.com. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 Our SOC wants to build a high-fidelity correlation rule in our SIEM to catch stealthy account persistence following an AiTM session hijack. What specific post-login credential modification event, when paired with a suspicious sign-in, indicates session compromise? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 Our SOC relies on static threat intelligence IP feeds to block EvilProxy and Tycoon 2FA landing pages at the secure web gateway. Threat actors are frequently rotating IPs. What dynamic domain monitoring and certificate inspection rules should be added to our web proxy policy to catch active AiTM proxy infrastructure? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 When analyzing network proxy logs during a suspected reverse-proxy phishing attack against Microsoft 365, what subtle cross-domain web request pattern specifically indicates that a proxy domain is relaying traffic to legitimate authentication infrastructure? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 After an attacker successfully captures a session cookie via EvilProxy, what cloud storage telemetry in Microsoft 365 should be audited to detect bulk intellectual property theft? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |