A security team is performing threat modeling for a hybrid environment consisting of on-prem Active Directory and Azure AD. The team wants to identify how an attacker could move from a compromised cloud identity to full on-prem domain dominance. Which modeling focus is MOST appropriate?
The correct answer is mapping trust relationships between identity systems. Hybrid identity environments introduce complex trust boundaries that attackers routinely exploit.
Modern breaches increasingly involve identity pivoting, where attackers compromise a cloud identity and abuse synchronization, federation, or conditional access misconfigurations to escalate into on-prem Active Directory. These attack paths often do not rely on software vulnerabilities at all.
Option A is too narrow and focuses only on technical exploits. Option C measures severity but does not model movement. Option D analyzes traffic but does not explain privilege escalation pathways.
By mapping trust relationships---such as Azure AD Connect synchronization, service principals, hybrid admin roles, and conditional access exclusions---defenders can identify chained attack paths that enable privilege escalation without exploiting code.
From a threat hunting standpoint, this modeling enables:
Hypothesis-driven hunts
Detection of abnormal role assumptions
Visibility into identity abuse
This approach aligns with attack path modeling, a critical evolution of traditional threat modeling for identity-centric environments. Therefore, option B is correct.
Kaitlyn
13 days agoRasheeda
18 days agoAshley
24 days agoChana
29 days agoJonelle
1 month agoDarci
1 month agoRodolfo
1 month agoAlethea
2 months agoColetta
2 months agoFrancoise
2 months agoJacquelyne
2 months agoCraig
2 months ago