A civic AD assessment identifies an enterprise certificate authority as a crown-jewel asset. How should the tester prioritize ADCS/CA review when it is in scope?
Select an answer to reveal the explanation.
Short Explanation
A CA that the domain trusts is like a badge printer that can mint official credentials. If that printer is soft, the blast radius can rival domain compromise stories. When ADCS is present and in scope, it earns crown-jewel attention — not a shrug.
Full Explanation
Active Directory Certificate Services and related certificate authorities can have outsized impact because trusted certificates influence authentication and authorization across the environment. When a CA is in scope, assessors should prioritize configuration and privilege review around ADCS as a high-value AD-adjacent target class. Dismissing CAs as “website SSL only” or limiting them to wireless surveys understates their role. Findings should stay at judgment and hardening priority — not exploit recipes.