CPENT · domain
Active Directory Attacks
Practise EC-Council Certified Penetration Testing Professional (CPENT) (CPENT) Active Directory Attacks practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Active Directory Attacks questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Active Directory Attacks
Active Directory Attacks questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Active Directory Attacks exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Active Directory Attacks questions (50)
Click any question to see the full explanation, or start a practice session above.
When executing BloodHound to map Active Directory attack paths, which collector option should be specified via SharpHound to gather computer local admin rights without requiring Domain Admin privileges?
Medium2Which native Windows command-line tool can be used by a penetration tester to view cached Kerberos tickets currently loaded in the user session?
Easy3An advanced adversary has gained Domain Administrator privileges and wants to establish stealthy, long-term persistence in Active Directory without relying solely on traditional user accounts or standard scheduled tasks. Which THREE advanced persistence mechanisms can be deployed in an Active Directory environment? (Choose THREE)
Hard4During an internal penetration test, an operator compromises a low-privileged domain user account and wishes to perform a Kerberoasting attack to harvest service principal name (SPN) tickets. Which standard utility included with Windows PowerShell or Sysinternals can be used to request these tickets without administrative privileges?
Easy5Which TWO configuration checks should a penetration tester perform when auditing an Active Directory domain for potential NTLM Relay vulnerabilities?
Medium6When generating a Silver Ticket using Impacket's ticketer.py, what specific piece of cryptographic material is required instead of the KRBTGT hash?
Easy7During a post-exploitation phase on a Windows workstation, a tester dumps LSASS memory and extracts an NTLM password hash. The tester then uses the CrackMapExec tool to authenticate to other workstations using this hash without cracking it first. What attack technique is being executed?
Easy8Which THREE conditions must be met for a successful Resource-Based Constrained Delegation (RBCD) attack against a target computer object?
Hard9Which TWO of the following Impacket tools can be utilized to perform credential dumping or secret extraction from Active Directory or target systems when valid administrator credentials are known?
Medium10A penetration tester is evaluating an Active Directory environment and discovers that LDAP signing is not enforced. Which attack technique does this misconfiguration directly facilitate?
Easy11A tester has located a domain user account configured with Constrained Delegation (S4U2Self / S4U2Proxy) pointing to a target service. What tool and module in Impacket can be used to leverage this delegation to obtain a TGS for a privileged user (e.g., Administrator)?
Medium12When executing a DCSync attack programmatically via Impacket's secretsdump.py, how does the tool interact with Active Directory to request password data without running code on the domain controller?
Hard13Which TWO tools are commonly used for analyzing BloodHound database outputs or querying attack paths during an Active Directory penetration test?
Medium14A penetration tester is performing an attack utilizing the PetitPotam (MS-EFSR) vulnerability against a domain controller. What is the primary objective of forcing the domain controller to authenticate via PetitPotam?
Medium15Which TWO methods can an operator use to mitigate or prevent detection while performing Kerberoasting during an internal penetration test?
Medium16A penetration tester has compromised an account that possesses the 'GenericAll' permission over a Group Policy Object (GPO) linked to the domain. How can this permission be leveraged to achieve remote code execution across systems affected by the GPO?
Medium17An operator has compromised an account with GenericAll permissions over a computer object in Active Directory. How can this permission be leveraged to achieve code execution on the target host?
Medium18In the context of AD CS abuse, which THREE vulnerabilities or template settings are categorized under certificate template misconfigurations that allow privilege escalation?
Hard19A pentester needs to exploit an AD CS vulnerability where a low-privileged user can enroll in a template that permits Client Authentication and has the 'ENROLLEE_SUPPLIES_SUBJECT' flag set. Which tool from Certipy can be used to request a certificate and subsequently authenticate as a high-privileged user?
Hard20An ethical hacker has compromised a machine account and discovered that it has 'GenericAll' or 'WriteDacl' privileges over a privileged domain group (such as Domain Admins). Which TWO techniques or actions can the operator perform using these permissions to escalate privileges? (Choose TWO)
Medium21A penetration tester identifies a user account with the 'Do not require Kerberos pre-authentication' (DONT_REQUIRE_PREAUTH) property enabled. Which attack can be performed against this account?
Easy22An ethical hacker has obtained the NTLM password hash of a local administrator account on a Windows workstation and wants to perform lateral movement using Pass-the-Hash (PtH). Which tool allows executing a command or spawning an interactive prompt on a remote system using only the NTLM hash without knowing the plaintext password?
Easy23A pentester successfully compromises a machine and obtains a valid Kerberos Ticket Granting Ticket (TGT) file (.ccache). To use this ticket for lateral movement on Linux using Impacket, which environment variable must be exported?
Medium24During an Active Directory Certificate Services (AD CS) assessment, a tester discovers that the 'ESC1' vulnerability is present. What specific misconfiguration defines ESC1 on a certificate template?
Hard25When analyzing BloodHound output, what visual edge or relationship indicates that user 'A' can modify the membership or attributes of group 'B'?
Easy26Which TWO of the following Active Directory enumeration methods or tools can be used by an unprivileged domain user to identify accounts configured with 'Do not require Kerberos preauthentication' (AS-REP roasting candidates)? (Choose TWO)
Easy27During a Red Team assessment against an enterprise network, an operator wants to execute a Silver Ticket attack against a specific service (e.g., CIFS) on a target server. What is a key operational advantage of a Silver Ticket compared to a Golden Ticket?
Medium28An attacker has retrieved the KRBTGT account hash and wants to forge a Golden Ticket. Which tool from the Impacket suite is specifically designed to perform this forgery offline and inject the ticket?
Hard29A pentester wants to execute a Shadow Credentials attack (Key Credential Link abuse) against a high-value user account in Active Directory. What permission on the target user object is required to successfully perform this attack?
Hard30Which TWO Active Directory mechanisms or configurations are commonly targeted during lateral movement to bypass traditional perimeter security and leverage built-in domain trust relationships?
Medium31Which THREE methods or attack primitives can be used to achieve domain escalation when an attacker has compromised an account with 'GenericAll' permissions over a Group Policy Object (GPO)?
Hard32During an Active Directory security review, an assessor examines Kerberos delegation configurations. Which THREE delegation misconfigurations or vulnerabilities represent high-risk attack vectors if exploited? (Choose THREE)
Hard33Which THREE tactics or actions are effective in defending against or detecting Golden Ticket attacks in an enterprise Active Directory environment?
Hard34An operator has gained administrative access to a subordinate domain in a multi-domain Active Directory forest and wishes to escalate privileges to Enterprise Admin across the entire forest. What object or group must be compromised to achieve forest-wide control?
Medium35When analyzing a compromised Active Directory environment using BloodHound, which THREE common node properties or paths typically signify a high-value target or an immediate path to Domain Admin?
Hard36An auditor is reviewing Active Directory Certificate Services and identifies ESC8. What exact AD CS endpoint is exploited during an ESC8 attack vector?
Hard37An attacker has identified an Active Directory Certificate Services (AD CS) template configured with the 'Enrollee Supplies Subject' flag enabled (EDITF_ATTRIBUTESUBJECTALTNAME2 is enabled on the CA), and the template permissions allow low-privileged domain users to enroll. Furthermore, the template allows client authentication. How can this misconfiguration (ESC1) be exploited?
Hard38Which TWO methods can an operator use to verify whether an account has successfully been granted DCSync privileges after modifying access control lists (ACLs)?
Medium39Which THREE techniques or remediation steps are recommended to secure Active Directory Certificate Services (AD CS) against certificate-based abuse vectors like ESC1 through ESC8?
Hard40Which THREE conditions or configurations make an Active Directory certificate template vulnerable to ESC3 (Enrollment Agent abuse)?
Hard41When conducting an advanced Active Directory penetration test, which THREE techniques can be used to extract or abuse credentials without interacting with LSASS directly on a domain controller?
Hard42An internal penetration tester is performing reconnaissance using BloodHound to map out attack paths in an Active Directory domain. Which automated data collection tool is officially supported and widely utilized to gather ACLs, session information, and object relationships for BloodHound ingestion?
Easy43Which TWO commands or tools are standard for performing AS-REP Roasting against an Active Directory domain from an external or internal position?
Medium44A penetration tester is attempting to perform Kerberoasting using Impacket. Which specific service principal name (SPN) format must be requested against the target domain controller to successfully extract TGS-AEAD tickets that can be cracked offline?
Easy45During an Active Directory assessment, an operator discovers that the KRBTGT account password has not been rotated in over ten years. They decide to craft a Golden Ticket to maintain persistent domain-wide access. Which critical piece of information, in addition to the KRBTGT NTLM hash and domain SID, is strictly required to generate a fully valid Golden Ticket that includes group membership and privilege attributes?
Hard46An operator has identified an Active Directory domain trust relationship where a trusted forest has 'SID History' filtering disabled (Quarantined Domain Trust set to disabled/unfiltered). What attack does this enable?
Hard47Which Active Directory right or permission allows a security principal to perform a DCSync attack, thereby replicating domain secrets?
Easy48An operator captures a valid Ticket Granting Ticket (TGT) for a domain user from memory and wants to inject it into their current session to access network resources without re-authenticating. Which tool and command syntax should be used to import this ticket into the local LSASS session on Windows?
Medium49Which TWO native Windows tools or Sysinternals utilities can be used by an operator during post-exploitation to dump credentials from the LSASS process memory?
Medium50An operator has discovered a computer object with Unconstrained Delegation enabled in Active Directory. How can this configuration be abused if a Domain Administrator account can be coerced to authenticate to it?
MediumOther domains
All CPENT exam domains
Frequently asked questions
- What does the Active Directory Attacks domain cover on the CPENT exam?
- Active Directory Attacks questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 50 Active Directory Attacks questions in the CPENT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Active Directory Attacks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.