Courseiva
Active Directory AttackshardMultiple SelectObjective-mapped

CPENT Active Directory Attacks Practice Question

Which THREE techniques or remediation steps are recommended to secure Active Directory Certificate Services (AD CS) against certificate-based abuse vectors like ESC1 through ESC8?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disable HTTP-based web enrollment or enforce HTTPS with Extended Protection for Authentication (EPA) enabled.

Securing AD CS involves disabling NTLM authentication on web enrollment endpoints, enabling Extended Protection for Authentication (EPA), disabling enrollee-supplied SANs on vulnerable templates, and auditing templates using tools like Certipy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable HTTP-based web enrollment or enforce HTTPS with Extended Protection for Authentication (EPA) enabled.

    Why this is correct

    EPA and HTTPS mitigation prevent NTLM relay attacks against ESC8.

  • Regularly audit AD CS infrastructure and templates using tools like Certipy or BloodHound.

    Why this is correct

    Proactive auditing identifies dangerous template permissions and misconfigurations.

  • Disable Kerberos pre-authentication across all domain controller computer accounts.

    Why it's wrong here

    Disabling pre-auth introduces vulnerabilities (AS-REP roasting) rather than securing AD CS.

  • Enforce unconstrained delegation on all certificate authority servers.

    Why it's wrong here

    Unconstrained delegation introduces massive security risks, violating hardening best practices.

  • Remove the 'ENROLLEE_SUPPLIES_SUBJECT' flag from certificate templates unless strictly required.

    Why this is correct

    Disabling enrollees from supplying alternative SANs mitigates ESC1.

About these practice questions

Courseiva writes every CPENT question from scratch — 276 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.