After a domain migration, a civic directory still shows SID History and related leftover privilege artifacts granting unexpected access. How should the tester treat that?
Select an answer to reveal the explanation.
Short Explanation
Old badges left in wallets after a building move still open doors. SID History and migration leftovers can carry forgotten privileges into the new directory. Sweep those artifacts; do not assume the move cleaned every right.
Full Explanation
SID History and similar migration residues can preserve historical group and access associations that produce unexpected effective rights in the current domain. Those artifacts are authorization-relevant, not inert metadata, and are not limited to Linux UID mapping. Their presence does not by itself prove a trust was never created. CPTS-style AD reviews should include migration leftover privilege as a misconfiguration class.