Courseiva
Active Directory AttackshardMultiple SelectObjective-mapped

CPENT Active Directory Attacks Practice Question

In the context of AD CS abuse, which THREE vulnerabilities or template settings are categorized under certificate template misconfigurations that allow privilege escalation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

ESC1: Enrollee supplies subject and template permits client authentication for low-privileged users

AD CS misconfigurations like ESC1 (enrollee supplies subject), ESC2 (any purpose EKU), and ESC3 (enrollment agent templates) represent common template-based vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ESC1: Enrollee supplies subject and template permits client authentication for low-privileged users

    Why this is correct

    ESC1 allows requesting certificates for arbitrary users.

  • ESC4: Low-privileged users have Write permissions (Modify/WriteDACL) over the certificate template

    Why this is correct

    ESC4 allows modifying template settings to introduce vulnerabilities like ESC1.

  • ESC10: Strict certificate mapping and strong SID binding enforced

    Why it's wrong here

    ESC10 represents hardening settings (KB5014754) that mitigate certificate mapping bypasses.

  • LDAP signing enforced across all domain controllers

    Why it's wrong here

    Enforcing LDAP signing is a hardening measure, not a vulnerability.

  • ESC8: HTTP-based enrollment endpoints permitting NTLM relay

    Why this is correct

    ESC8 leverages web enrollment endpoints for NTLM relay attacks.

About these practice questions

This CPENT question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.