Courseiva

CPENT · topic practice

Active Directory Attacks practice questions

Practise EC-Council Certified Penetration Testing Professional (CPENT) (CPENT) Active Directory Attacks practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Active Directory Attacks

What the exam tests

What to know about Active Directory Attacks

Active Directory Attacks questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Active Directory Attacks exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Active Directory Attacks questions

20 questions · select your answer, then reveal the explanation

A pentester successfully compromises a machine and obtains a valid Kerberos Ticket Granting Ticket (TGT) file (.ccache). To use this ticket for lateral movement on Linux using Impacket, which environment variable must be exported?

An attacker has retrieved the KRBTGT account hash and wants to forge a Golden Ticket. Which tool from the Impacket suite is specifically designed to perform this forgery offline and inject the ticket?

When executing BloodHound to map Active Directory attack paths, which collector option should be specified via SharpHound to gather computer local admin rights without requiring Domain Admin privileges?

A penetration tester identifies a user account with the 'Do not require Kerberos pre-authentication' (DONT_REQUIRE_PREAUTH) property enabled. Which attack can be performed against this account?

During an Active Directory Certificate Services (AD CS) assessment, a tester discovers that the 'ESC1' vulnerability is present. What specific misconfiguration defines ESC1 on a certificate template?

During a post-exploitation phase on a Windows workstation, a tester dumps LSASS memory and extracts an NTLM password hash. The tester then uses the CrackMapExec tool to authenticate to other workstations using this hash without cracking it first. What attack technique is being executed?

An operator has compromised an account with GenericAll permissions over a computer object in Active Directory. How can this permission be leveraged to achieve code execution on the target host?

A penetration tester is attempting to perform Kerberoasting using Impacket. Which specific service principal name (SPN) format must be requested against the target domain controller to successfully extract TGS-AEAD tickets that can be cracked offline?

Which Active Directory right or permission allows a security principal to perform a DCSync attack, thereby replicating domain secrets?

A tester has located a domain user account configured with Constrained Delegation (S4U2Self / S4U2Proxy) pointing to a target service. What tool and module in Impacket can be used to leverage this delegation to obtain a TGS for a privileged user (e.g., Administrator)?

A pentester needs to exploit an AD CS vulnerability where a low-privileged user can enroll in a template that permits Client Authentication and has the 'ENROLLEE_SUPPLIES_SUBJECT' flag set. Which tool from Certipy can be used to request a certificate and subsequently authenticate as a high-privileged user?

An operator has identified an Active Directory domain trust relationship where a trusted forest has 'SID History' filtering disabled (Quarantined Domain Trust set to disabled/unfiltered). What attack does this enable?

An auditor is reviewing Active Directory Certificate Services and identifies ESC8. What exact AD CS endpoint is exploited during an ESC8 attack vector?

When analyzing BloodHound output, what visual edge or relationship indicates that user 'A' can modify the membership or attributes of group 'B'?

A penetration tester is performing an attack utilizing the PetitPotam (MS-EFSR) vulnerability against a domain controller. What is the primary objective of forcing the domain controller to authenticate via PetitPotam?

When generating a Silver Ticket using Impacket's ticketer.py, what specific piece of cryptographic material is required instead of the KRBTGT hash?

An operator has discovered a computer object with Unconstrained Delegation enabled in Active Directory. How can this configuration be abused if a Domain Administrator account can be coerced to authenticate to it?

A pentester wants to execute a Shadow Credentials attack (Key Credential Link abuse) against a high-value user account in Active Directory. What permission on the target user object is required to successfully perform this attack?

Which native Windows command-line tool can be used by a penetration tester to view cached Kerberos tickets currently loaded in the user session?

A penetration tester is evaluating an Active Directory environment and discovers that LDAP signing is not enforced. Which attack technique does this misconfiguration directly facilitate?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Active Directory Attacks sessions

Start a Active Directory Attacks only practice session

Every question in these sessions is drawn from the Active Directory Attacks domain — nothing else.

Related practice questions

Related CPENT topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CPENT exam test about Active Directory Attacks?
Active Directory Attacks questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Active Directory Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Active Directory Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CPENT topics?
Use the topic links above to move to related areas, or go back to the CPENT question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CPENT exam covers. They are not copied from any real exam or dump site.