A transit AD assessment discovers a Group Policy Object that is writable by a low-privilege group and linked to OUs holding high-value servers. How should the tester frame the finding?
Select an answer to reveal the explanation.
Short Explanation
If someone can edit a GPO aimed at the servers that run the transit system, they can push settings those machines will obey. That is escalation in AD clothing — not a wallpaper joke. Who can write GPOs linked to crown-jewel OUs is a core control question.
Full Explanation
Group Policy Objects applied to high-value organizational units can enforce configuration, software deployment, and security settings across many systems. Write access for low-privilege principals to such GPOs creates a practical privilege-escalation and persistence path. Wallpaper-only dismissals and assumptions that Domain Admin is already required both understate the risk. Assessments should identify who can edit GPOs linked to important OUs and treat excessive rights as significant Active Directory findings.