Courseiva
Active Directory AttackshardMultiple SelectObjective-mapped

CPENT Active Directory Attacks Practice Question

Which THREE conditions or configurations make an Active Directory certificate template vulnerable to ESC3 (Enrollment Agent abuse)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The template includes the Certificate Request Agent EKU (Enrollment Agent functionality).

ESC3 involves a certificate template configured as an Enrollment Agent (containing the Certificate Request Agent EKU), allowing enrollment by low-privileged users, and permitting issuance of certificates on behalf of other users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The template includes the Certificate Request Agent EKU (Enrollment Agent functionality).

    Why this is correct

    Enrollment agent EKUs allow requesting certificates on behalf of other principals.

  • Low-privileged users have enrollment rights over the template.

    Why this is correct

    Attackers must be able to enroll in the enrollment agent template to initiate the attack.

  • The CA requires Manager Approval for all issued certificates.

    Why it's wrong here

    Manager approval blocks automated ESC3 exploitation unless bypassed.

  • The application policy constraints or authorized signatures are missing or overly permissive.

    Why this is correct

    Permissive template settings allow the agent to request arbitrary target certificates without restriction.

  • The domain functional level is set to Windows Server 2003.

    Why it's wrong here

    AD CS vulnerabilities exist independently of old functional levels.

About these practice questions

Courseiva writes every CPENT question from scratch — 274 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.