Courseiva

PEN-200 · domain

Active Directory Attacks

This domain covers post-compromise Active Directory tradecraft on Windows estates: enumerating ACLs and delegation with BloodHound and PowerView, abusing Kerberos (Kerberoasting, AS-REP roasting, delegation, DCSync), and pivoting from a standard user to Domain Admin. Questions test tool selection, attack mechanics, and required privileges rather than raw exploitation steps.

22 questions5 easy10 medium7 hard

Focused practice

Practice Active Directory Attacks questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Active Directory Attacks

You must chain enumeration to exploitation: read BloodHound/PowerView output, pick the correct ACL or delegation abuse, and execute it with Mimikatz, Impacket, or NetExec. The critical thing is verifying the exact privilege a technique requires before running it, so you avoid lockouts and access-denied failures.

Reading BloodHound edges like GenericAll, WriteDACL, and ForceChangePassword to plan ACL abuse paths

Executing DCSync with Mimikatz lsadump::dcsync or Impacket secretsdump against a domain controller

Abusing Kerberos delegation: unconstrained, constrained, and resource-based constrained delegation with SeEnableDelegationPrivilege

Enumerating accessible systems with CrackMapExec or NetExec smb using the compromised credential safely

Watch out for

Common Active Directory Attacks exam traps

  • ▸Confusing GenericAll on a computer object with local admin: it grants object control, so you must still add a computer account or reset the machine password to get a shell.
  • ▸Running DCSync without Replicating Directory Changes and Replicating Directory Changes All rights, or from an account lacking them, causing access denied.
  • ▸Triggering account lockout by spraying the plaintext password across many hosts instead of checking one host or using a lockout-aware tool.

Question index

All Active Directory Attacks questions (22)

Click any question to see the full explanation, or start a practice session above.

1

Which attack involves an attacker capturing NTLM authentication traffic from a user and relaying it to another machine to gain unauthorized access?

Medium
2

Which of the following describes the primary difference between a Golden Ticket and a Silver Ticket attack in an Active Directory environment?

Easy
3

You have compromised a domain user account and discovered that the domain controller is running Windows Server 2016. You want to extract the KRBTGT account hash to create a Golden Ticket. Which two conditions are necessary to successfully perform a DCSync attack to obtain the KRBTGT hash? (Choose two.)

Hard
4

You have captured an NTLM hash of a domain user. Why is performing a Pass-the-Hash (PtH) attack often more effective than attempting to crack the hash for the cleartext password?

Medium
5

You have obtained credentials for a domain user and want to enumerate Active Directory to find misconfigured ACLs that allow privilege escalation. You need to collect data that maps relationships between users, groups, computers, and sessions, and you want to visualize shortest paths to Domain Admin. Which tool and collection method best fits this requirement?

Medium
6

Which THREE of the following are valid techniques for achieving persistence within an Active Directory environment?

Hard
7

During an internal penetration test you compromise a domain-joined workstation and recover a user's NTLMv2 hash via a forced authentication attempt. SMB signing is enforced on all servers, and the client will not initiate outbound SMB connections. You want to crack the credential offline rather than relay it. Which approach is most appropriate?

Medium
8

Which of the following describes the 'GPP Password' vulnerability?

Medium
9

What is the primary objective of an 'AS-REP Roasting' attack?

Easy
10

Which tool is primarily used to perform BloodHound data collection to map out attack paths within an Active Directory environment?

Easy
11

During an internal Active Directory assessment, you have compromised a standard domain user account. You run BloodHound and identify that this user has the 'GenericAll' permission over a computer object named WEB01. You want to leverage this permission to compromise WEB01 and obtain administrative access to it. Which of the following is the most direct and reliable technique to achieve this?

Hard
12

Which of the following conditions is required to execute a successful Pass-the-Hash (PtH) attack against a target workstation?

Easy
13

During a penetration test, you have gained access to a workstation and extracted a Kerberos TGT for a domain user. You want to use this ticket to access a file share on another server without knowing the user's password. Which technique should you employ?

Hard
14

You have compromised a domain user account and want to escalate privileges by abusing a misconfigured Group Policy Object (GPO). You discover that the GPO is linked to an Organizational Unit (OU) containing privileged servers and that the domain user has write permissions on the GPO. Which action should you take to escalate privileges?

Medium
15

You have obtained a low-privileged domain user account and are performing internal enumeration. You identify a computer object in the domain where the 'ms-MCS-AdmPwd' attribute is readable by your user account. Which attack path does this vulnerability facilitate?

Medium
16

Why does enabling 'SMB Signing' prevent NTLM relay attacks?

Hard
17

During an internal assessment you compromise a workstation and recover a Kerberos TGS ticket from memory that belongs to a service account. Analysis shows the ticket was encrypted with the RC4-HMAC cipher using a key derived from the service account's password hash. You want to recover the plaintext password of that service account offline. Which action should you take?

Medium
18

During an internal assessment, you compromise a workstation and recover a cached domain credential hash for a user who previously logged on. You want to use this hash to authenticate to a file server on the same network, but you do not know the plaintext password. Which of the following tools is specifically designed to perform Pass-the-Hash authentication from a Linux-based attack platform?

Medium
19

When performing a DCSync attack, what is the core mechanism being exploited?

Medium
20

You have compromised a service account that has the SeEnableDelegationPrivilege right on a domain controller. You want to abuse Kerberos delegation to gain access to a target server's file share. Which two steps are required to configure and exploit unconstrained delegation on a controlled computer object? (Choose two.)

Hard
21

You have obtained a plaintext password for a domain user and want to quickly identify which domain-joined systems the account can access with local administrative rights, without triggering account lockout. Which approach is most appropriate?

Easy
22

During an Active Directory penetration test, you have obtained Domain Admin privileges. To maintain persistent access, you decide to create a Golden Ticket. Which two of the following pieces of information are required to forge a valid Golden Ticket? (Choose two.)

Hard

Frequently asked questions

What does the Active Directory Attacks domain cover on the PEN-200 exam?
You must chain enumeration to exploitation: read BloodHound/PowerView output, pick the correct ACL or delegation abuse, and execute it with Mimikatz, Impacket, or NetExec. The critical thing is verifying the exact privilege a technique requires before running it, so you avoid lockouts and access-denied failures.
How many questions are in this domain?
This page lists all 22 Active Directory Attacks questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Active Directory Attacks questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
offsec-oscp OFFSEC-OSCP active directory attacks Practice Questions