PEN-200 · domain
Active Directory Attacks
This domain covers post-compromise Active Directory tradecraft on Windows estates: enumerating ACLs and delegation with BloodHound and PowerView, abusing Kerberos (Kerberoasting, AS-REP roasting, delegation, DCSync), and pivoting from a standard user to Domain Admin. Questions test tool selection, attack mechanics, and required privileges rather than raw exploitation steps.
Focused practice
Practice Active Directory Attacks questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Active Directory Attacks
You must chain enumeration to exploitation: read BloodHound/PowerView output, pick the correct ACL or delegation abuse, and execute it with Mimikatz, Impacket, or NetExec. The critical thing is verifying the exact privilege a technique requires before running it, so you avoid lockouts and access-denied failures.
Reading BloodHound edges like GenericAll, WriteDACL, and ForceChangePassword to plan ACL abuse paths
Executing DCSync with Mimikatz lsadump::dcsync or Impacket secretsdump against a domain controller
Abusing Kerberos delegation: unconstrained, constrained, and resource-based constrained delegation with SeEnableDelegationPrivilege
Enumerating accessible systems with CrackMapExec or NetExec smb using the compromised credential safely
Watch out for
Common Active Directory Attacks exam traps
- ▸Confusing GenericAll on a computer object with local admin: it grants object control, so you must still add a computer account or reset the machine password to get a shell.
- ▸Running DCSync without Replicating Directory Changes and Replicating Directory Changes All rights, or from an account lacking them, causing access denied.
- ▸Triggering account lockout by spraying the plaintext password across many hosts instead of checking one host or using a lockout-aware tool.
Question index
All Active Directory Attacks questions (22)
Click any question to see the full explanation, or start a practice session above.
Which attack involves an attacker capturing NTLM authentication traffic from a user and relaying it to another machine to gain unauthorized access?
Medium2Which of the following describes the primary difference between a Golden Ticket and a Silver Ticket attack in an Active Directory environment?
Easy3You have compromised a domain user account and discovered that the domain controller is running Windows Server 2016. You want to extract the KRBTGT account hash to create a Golden Ticket. Which two conditions are necessary to successfully perform a DCSync attack to obtain the KRBTGT hash? (Choose two.)
Hard4You have captured an NTLM hash of a domain user. Why is performing a Pass-the-Hash (PtH) attack often more effective than attempting to crack the hash for the cleartext password?
Medium5You have obtained credentials for a domain user and want to enumerate Active Directory to find misconfigured ACLs that allow privilege escalation. You need to collect data that maps relationships between users, groups, computers, and sessions, and you want to visualize shortest paths to Domain Admin. Which tool and collection method best fits this requirement?
Medium6Which THREE of the following are valid techniques for achieving persistence within an Active Directory environment?
Hard7During an internal penetration test you compromise a domain-joined workstation and recover a user's NTLMv2 hash via a forced authentication attempt. SMB signing is enforced on all servers, and the client will not initiate outbound SMB connections. You want to crack the credential offline rather than relay it. Which approach is most appropriate?
Medium8Which of the following describes the 'GPP Password' vulnerability?
Medium9What is the primary objective of an 'AS-REP Roasting' attack?
Easy10Which tool is primarily used to perform BloodHound data collection to map out attack paths within an Active Directory environment?
Easy11During an internal Active Directory assessment, you have compromised a standard domain user account. You run BloodHound and identify that this user has the 'GenericAll' permission over a computer object named WEB01. You want to leverage this permission to compromise WEB01 and obtain administrative access to it. Which of the following is the most direct and reliable technique to achieve this?
Hard12Which of the following conditions is required to execute a successful Pass-the-Hash (PtH) attack against a target workstation?
Easy13During a penetration test, you have gained access to a workstation and extracted a Kerberos TGT for a domain user. You want to use this ticket to access a file share on another server without knowing the user's password. Which technique should you employ?
Hard14You have compromised a domain user account and want to escalate privileges by abusing a misconfigured Group Policy Object (GPO). You discover that the GPO is linked to an Organizational Unit (OU) containing privileged servers and that the domain user has write permissions on the GPO. Which action should you take to escalate privileges?
Medium15You have obtained a low-privileged domain user account and are performing internal enumeration. You identify a computer object in the domain where the 'ms-MCS-AdmPwd' attribute is readable by your user account. Which attack path does this vulnerability facilitate?
Medium16Why does enabling 'SMB Signing' prevent NTLM relay attacks?
Hard17During an internal assessment you compromise a workstation and recover a Kerberos TGS ticket from memory that belongs to a service account. Analysis shows the ticket was encrypted with the RC4-HMAC cipher using a key derived from the service account's password hash. You want to recover the plaintext password of that service account offline. Which action should you take?
Medium18During an internal assessment, you compromise a workstation and recover a cached domain credential hash for a user who previously logged on. You want to use this hash to authenticate to a file server on the same network, but you do not know the plaintext password. Which of the following tools is specifically designed to perform Pass-the-Hash authentication from a Linux-based attack platform?
Medium19When performing a DCSync attack, what is the core mechanism being exploited?
Medium20You have compromised a service account that has the SeEnableDelegationPrivilege right on a domain controller. You want to abuse Kerberos delegation to gain access to a target server's file share. Which two steps are required to configure and exploit unconstrained delegation on a controlled computer object? (Choose two.)
Hard21You have obtained a plaintext password for a domain user and want to quickly identify which domain-joined systems the account can access with local administrative rights, without triggering account lockout. Which approach is most appropriate?
Easy22During an Active Directory penetration test, you have obtained Domain Admin privileges. To maintain persistent access, you decide to create a Golden Ticket. Which two of the following pieces of information are required to forge a valid Golden Ticket? (Choose two.)
HardOther domains
All PEN-200 exam domains
Frequently asked questions
- What does the Active Directory Attacks domain cover on the PEN-200 exam?
- You must chain enumeration to exploitation: read BloodHound/PowerView output, pick the correct ACL or delegation abuse, and execute it with Mimikatz, Impacket, or NetExec. The critical thing is verifying the exact privilege a technique requires before running it, so you avoid lockouts and access-denied failures.
- How many questions are in this domain?
- This page lists all 22 Active Directory Attacks questions in the PEN-200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Active Directory Attacks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.