Courseiva
Active Directory Attacks →hardMultiple Choice

PEN-200 Active Directory Attacks Practice Question

During an internal Active Directory assessment, you have compromised a standard domain user account. You run BloodHound and identify that this user has the 'GenericAll' permission over a computer object named WEB01. You want to leverage this permission to compromise WEB01 and obtain administrative access to it. Which of the following is the most direct and reliable technique to achieve this?

⚠ Common exam trap

The trap here is assuming that GenericAll over a computer object only allows resetting the machine account password or that it must be combined with other misconfigurations, when in fact it directly enables shadow credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the GenericAll permission to perform a shadow credentials attack by adding a Key Credential to the msDS-KeyCredentialLink attribute of WEB01.

GenericAll over a computer object allows full control, including modifying the msDS-KeyCredentialLink attribute. By adding a Key Credential, an attacker can authenticate as the computer account via PKINIT and obtain a TGT, effectively taking over the machine. This shadow credentials technique is direct and does not require cracking or additional accounts, making it the most efficient path to compromise WEB01.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use the GenericAll permission to perform a shadow credentials attack by adding a Key Credential to the msDS-KeyCredentialLink attribute of WEB01.

    Why this is correct

    With GenericAll on a computer object, you can modify the msDS-KeyCredentialLink attribute to add a public key, then authenticate as that computer using PKINIT. This is known as a shadow credentials attack and directly grants you a ticket-granting ticket (TGT) for the machine account, allowing administrative access to WEB01. It is a direct and reliable method.

  • ✗

    Use the GenericAll permission to perform a targeted Kerberoasting attack by setting an SPN on a user account you control, then request a service ticket.

    Why it's wrong here

    GenericAll over a computer object does not grant the right to modify user objects. Targeted Kerberoasting requires write permissions over a user account to set an SPN. This option misinterprets the scope of the permission; the GenericAll is on WEB01, not on a user, so this action is not possible with the given access.

  • ✗

    Perform a Kerberoasting attack against the machine account of WEB01 to obtain its hash and then crack it offline.

    Why it's wrong here

    Machine accounts have complex, automatically rotated passwords, making offline cracking infeasible. Kerberoasting targets accounts with Service Principal Names (SPNs) and requests a service ticket, but the resulting hash is for the service account, not the machine account itself. This approach would not yield usable credentials for WEB01 in a reasonable timeframe.

  • ✗

    Use the GenericAll permission to perform a resource-based constrained delegation attack by modifying the msDS-AllowedToActOnBehalfOfOtherIdentity attribute.

    Why it's wrong here

    Resource-based constrained delegation (RBCD) is a valid technique, but it requires creating or controlling a computer account and configuring it to impersonate users to WEB01. While GenericAll on WEB01 allows setting the attribute, this is a multi-step process that also requires a controlled account with an SPN. It is less direct than other options.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.