Active Directory Enumeration & Attacks
CPTS · 55 questions
- After gaining a foothold on a city domain-joined laptop, what should the tester prioritize first for Active Directory situational awareness?
- A county asks why Active Directory remains a large attack surface even when OS patch levels look solid. What explanation best fits?
- A municipal tester proposes running every Active Directory attack tool simultaneously on day one. What is the better professional approach?
- A library engagement needs a foundation for later AD attack-path planning. Which enumeration class best builds that map?
- A transit engineer finds unconstrained delegation configured on a server account. How should this be treated in the assessment narrative?
- A city service account has SPNs registered and is exempt from the strong password policy. Which risk class should the tester highlight?
- During a county AD review, several users are found with Kerberos pre-authentication disabled. What does that configuration class represent?
- A municipal IT group places Domain Admin rights on many day-to-day admin accounts. What finding theme should the tester raise?
- A civic GPO grants local administrator rights on workstations to a broad user group. Why is this a significant AD-related finding?
- A water utility still allows legacy LM or NTLMv1 preference in parts of the environment. What risk awareness should the tester communicate?
- A city assessment finds printers and servers that accept NTLM authentication without required signing. How should this configuration class be framed?
- A county OU ACL grants a helpdesk group Full Control over user objects. What should the tester conclude?
- A library domain allows excessive machine-account creation or join rights for ordinary users. Why does that matter conceptually?
- A transit authority's AD CS deployment includes overly permissive certificate templates. How should the tester characterize the issue?
- A city CISO asks what BloodHound-class AD graphing tools are for. Which explanation is accurate?
- A municipal forest maintains an external trust to a vendor domain. What should the tester do conceptually regarding that trust?
- A county assessment finds plaintext passwords in AD descriptions or scripts stored in SYSVOL. What finding class does this represent?
- A civic application service runs as Domain Admin without a strong justification. What recommendation aligns with AD least privilege?
- A city GPO legacy setting disables SMB signing domain-wide. What conceptual link should the tester make in the report?
- A library's LDAP configuration allows anonymous or overly broad read of sensitive directory attributes. What should the tester flag?
- A transit administrator uses the same password on a personal Domain Admin account and a daily workstation login. What hygiene lesson should the report emphasize?
- A municipal Windows estate has no LAPS-class local administrator password solution, so many workstations share the same local admin password. What risk should the tester highlight?
- A county discovers constrained Kerberos delegation configured on several service accounts. How should the assessment treat that finding?
- From the approved test VLAN, a city domain controller still permits null-session enumeration of users and shares. What should the tester report?
- A civic tiered-administration model exists on paper, yet operators routinely use Domain Admin credentials inside ordinary email and browsing sessions. What concept should the finding stress?
- A water utility domain still runs unsupported domain controllers. How should the tester prioritize that observation?
- A county places a read-only domain controller at a lightly secured branch with a weak password-caching policy. What AD design risk is most relevant?
- After cracking one standard user hash, a municipal stakeholder asks whether that automatically equals Domain Admin. What is the correct response?
- A city finds Print Spooler-related remote capabilities still enabled on domain controllers contrary to hardening guidance. How should that be framed?
- A library Active Directory ACL lets a helpdesk-related group modify membership of an Administrators-tier group. What control question does this raise?
- A transit domain configures extremely long Kerberos ticket lifetimes. What conceptual risk should the report call out?
- During business hours, a municipal tester begins a very large, noisy Active Directory data pull that conflicts with the agreed RoE timing. What should the tester do?
- A county asks how local administrator rights on a workstation differ from domain user rights when planning Active Directory attack paths. What distinction matters most?
- A city still has legacy Windows hosts domain-joined with weak local controls. How should the tester treat them in an AD path assessment?
- A civic forest shows poor handling of inter-domain trust secrets and related trust passwords. What concept should the finding emphasize?
- A municipal GPO broadly disables Defender-class endpoint protections across domain-joined hosts. What should the assessment report?
- A county finds many computer accounts with machine passwords that have not rotated for an unusually long time. What hygiene theme applies?
- A transit Active Directory site topology is broken, producing odd authentication routing during the assessment. Why does that matter?
- A city helpdesk group can reset passwords on privileged user accounts. What risk should be highlighted?
- A library stores backup Domain Admin credentials in a ticketing system readable by many staff. How should identity risk be framed?
- A municipal engagement objective is proving a path to a crown-jewel file server via Active Directory. The tester already has a viable path but considers dumping NTDS "for completeness." What methodology stance is correct?
- A county asks whether Azure AD / Entra hybrid identity topics are automatically core to a CPTS-style on-prem Active Directory engagement. What is the right scope stance?
- A city finds unconstrained Kerberos authentication delegation enabled on a web server account. Why is that significant?
- A water plant vendor account remains in Domain Admins "temporarily" for years. What should the finding stress?
- After a domain migration, a civic directory still shows SID History and related leftover privilege artifacts granting unexpected access. How should the tester treat that?
- A county AD review finds DCSync-class replication rights granted to a normal user account that is not a domain controller. What should the tester treat as the core risk?
- During a municipal AD engagement, an anxious stakeholder asks the tester to “disable the entire domain to stop the test.” What is the professional next step?
- A transit AD assessment discovers a Group Policy Object that is writable by a low-privilege group and linked to OUs holding high-value servers. How should the tester frame the finding?
- A city IT lead asks why clock skew between workstations and domain controllers matters for Kerberos. What awareness-level answer is most accurate?
- A library’s compromise-recovery plan for Active Directory never mentions the krbtgt account password. What recovery-hygiene point should the tester emphasize?
- A county gold image used for fleet builds embeds a domain-join credential in the template. What AD-adjacent risk should the assessment highlight?
- A municipal AD security review finds that privileged group membership and ACL changes are not monitored. What operational gap does that primarily create?
- A city engagement asks how Active Directory enumeration differs when the tester has a valid domain user versus working from a non-domain foothold. What is the key visibility contrast?
- A civic AD assessment identifies an enterprise certificate authority as a crown-jewel asset. How should the tester prioritize ADCS/CA review when it is in scope?
- A municipal tester proposes spraying AD passwords during the city’s lunch peak without checking lockout policy. What constraint should shape that decision first?