A municipal AD security review finds that privileged group membership and ACL changes are not monitored. What operational gap does that primarily create?
Select an answer to reveal the explanation.
Short Explanation
If nobody is watching who gets added to Domain Admins or who suddenly owns a critical OU ACL, bad changes can sit there quietly. Detection is half the AD defense story — rights without eyes on them are a blind spot.
Full Explanation
Privileged group membership and sensitive ACL modifications are high-value signals for Active Directory security operations. Without auditing and alerting on those changes, defenders may miss escalation paths and persistence that alter directory control. Theme permissions, ticket lifetimes, and DNS scavenging are separate topics. Assessments should recommend monitoring and review workflows for privileged AD changes as a core detection control.