PEN-200 Active Directory Attacks Practice Question
During an internal Active Directory assessment, you have compromised a standard domain user account. You run BloodHound and identify that this user has the 'GenericAll' permission over a computer object named WEB01. You want to leverage this permission to compromise WEB01 and obtain administrative access to it. Which of the following is the most direct and reliable technique to achieve this?
⚠ Common exam trap
The trap here is assuming that GenericAll over a computer object only allows resetting the machine account password or that it must be combined with other misconfigurations, when in fact it directly enables shadow credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the GenericAll permission to perform a shadow credentials attack by adding a Key Credential to the msDS-KeyCredentialLink attribute of WEB01.
GenericAll over a computer object allows full control, including modifying the msDS-KeyCredentialLink attribute. By adding a Key Credential, an attacker can authenticate as the computer account via PKINIT and obtain a TGT, effectively taking over the machine. This shadow credentials technique is direct and does not require cracking or additional accounts, making it the most efficient path to compromise WEB01.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the GenericAll permission to perform a shadow credentials attack by adding a Key Credential to the msDS-KeyCredentialLink attribute of WEB01.
Why this is correct
With GenericAll on a computer object, you can modify the msDS-KeyCredentialLink attribute to add a public key, then authenticate as that computer using PKINIT. This is known as a shadow credentials attack and directly grants you a ticket-granting ticket (TGT) for the machine account, allowing administrative access to WEB01. It is a direct and reliable method.
- ✗
Use the GenericAll permission to perform a targeted Kerberoasting attack by setting an SPN on a user account you control, then request a service ticket.
Why it's wrong here
GenericAll over a computer object does not grant the right to modify user objects. Targeted Kerberoasting requires write permissions over a user account to set an SPN. This option misinterprets the scope of the permission; the GenericAll is on WEB01, not on a user, so this action is not possible with the given access.
- ✗
Perform a Kerberoasting attack against the machine account of WEB01 to obtain its hash and then crack it offline.
Why it's wrong here
Machine accounts have complex, automatically rotated passwords, making offline cracking infeasible. Kerberoasting targets accounts with Service Principal Names (SPNs) and requests a service ticket, but the resulting hash is for the service account, not the machine account itself. This approach would not yield usable credentials for WEB01 in a reasonable timeframe.
- ✗
Use the GenericAll permission to perform a resource-based constrained delegation attack by modifying the msDS-AllowedToActOnBehalfOfOtherIdentity attribute.
Why it's wrong here
Resource-based constrained delegation (RBCD) is a valid technique, but it requires creating or controlling a computer account and configuring it to impersonate users to WEB01. While GenericAll on WEB01 allows setting the attribute, this is a multi-step process that also requires a controlled account with an SPN. It is less direct than other options.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.