A county asks why Active Directory remains a large attack surface even when OS patch levels look solid. What explanation best fits?
Select an answer to reveal the explanation.
Short Explanation
Patches fix bugs; they do not fix 'too many Domain Admins' or a messy trust. AD is a giant identity city — streets, keys, and shortcuts matter as much as whether the doors got a firmware update. Misconfigs and trusts keep the surface large.
Full Explanation
Active Directory exposure frequently stems from complexity: delegation settings, ACLs, trusts, certificate services, and privilege sprawl. Missing OS patches are only one risk class and may be well managed while identity misconfigurations remain. Antivirus on member servers does not remove directory relationship abuse paths. Understanding that distinction helps clients prioritize identity hygiene alongside patching.