20+ practice questions focused on Active Directory Attacks — one of the most tested topics on the OffSec PEN-200 / OSCP Concepts exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Active Directory Attacks PracticeWhen assessing Active Directory, which TWO of the following configurations are considered high-risk misconfigurations that commonly lead to full domain compromise?
Explanation: Unconstrained delegation allows a server to impersonate any user who connects to it, potentially capturing a Domain Admin's TGT. Similarly, weak access control lists (ACLs) on privileged objects, such as 'GenericAll' over a Domain Admin account, allow a standard user to reset the admin password or modify group membership. Both provide direct pathways to domain escalation and are common targets in professional penetration testing engagements.
In an Active Directory environment, what is the primary security risk associated with the 'Account is sensitive and cannot be delegated' attribute on a user account?
Explanation: Actually, this attribute is a security control that prevents an account's credentials from being delegated to other services. The question asks for the risk associated with it, which is a conceptual trick; the risk is the *lack* of this setting on highly privileged accounts. When this attribute is NOT set on a Domain Admin, their credentials can be delegated to compromised servers, allowing attackers to hijack them.
You have compromised a low-privilege user account in an Active Directory forest. After enumerating the domain, you identify that the 'Pre-Windows 2000 Compatible Access' group contains the 'Authenticated Users' group. Which attack vector is most directly facilitated by this specific misconfiguration?
Explanation: The 'Pre-Windows 2000 Compatible Access' group grants members read access to sensitive user attributes. By default, this group's inclusion of Authenticated Users allows any domain user to perform a DCSync attack or extract sensitive data like LAPS passwords or BitLocker recovery keys if permissions are inherited. This is a critical vector because it bypasses standard delegation controls, turning low-privilege access into a potential full domain compromise via credential harvesting or attribute manipulation.
You have gained local administrator access to a workstation where a Domain Admin recently logged in. You suspect the user's credentials may be cached in memory. Which TWO techniques would allow you to extract these credentials from the LSASS process?
Explanation: Extracting credentials from LSASS is a foundational post-exploitation task in AD environments. Memory dumping techniques allow for offline analysis using tools like Mimikatz or Pypykatz. Understanding these methods is vital for an OSCP candidate because it bridges the gap between local system exploitation and domain-wide movement, highlighting the necessity of protecting privileged sessions on endpoints and disabling WDigest or clearing cached credentials to prevent immediate escalation to full domain compromise.
You are performing a domain enumeration and want to identify potential pathways to escalate privileges using GPO-based misconfigurations. Which THREE of the following conditions might indicate a GPO that can be abused for privilege escalation?
Explanation: GPOs are a common source of privilege escalation because they often contain cached credentials, scripts running with SYSTEM privileges, or insecure file permissions. Identifying these misconfigurations is a critical skill for an OSCP student to move from a standard user to a local admin on domain-joined machines. Understanding these specific vectors allows for the weaponization of Group Policy Objects that are improperly secured or assigned to sensitive groups.
+15 more Active Directory Attacks questions available
Practice all Active Directory Attacks questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Active Directory Attacks. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Active Directory Attacks questions on the PEN-200 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Active Directory Attacks is tested as part of the OffSec PEN-200 / OSCP Concepts blueprint. Practicing with targeted Active Directory Attacks questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free PEN-200 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Active Directory Attacks is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Active Directory Attacks practice session with instant scoring and detailed explanations.
Start Active Directory Attacks Practice →