Courseiva

CCNA Active Directory Attacks Questions

22 questions · Active Directory Attacks topic · All types, answers revealed

1
MCQmedium

Which attack involves an attacker capturing NTLM authentication traffic from a user and relaying it to another machine to gain unauthorized access?

A.Kerberoasting
B.DCSync
C.NTLM Relay
D.Golden Ticket
AnswerC

NTLM Relay is the process of intercepting authentication requests and forwarding them to a target machine. If successful, the attacker gains access to the target host with the privileges of the authenticated user. This attack is highly effective against environments where SMB signing is not enforced on network servers.

Why this answer

NTLM Relay involves capturing authentication requests from a client and forwarding them to a target server. If the target server allows NTLM authentication and does not have protections like SMB signing enabled, the server will accept the relayed authentication as if it came from the original user. This allows the attacker to impersonate the user and execute commands or access files on the target server.

Exam trap

Candidates often confuse NTLM relaying with credential harvesting. Relaying is a real-time attack that forwards authentication traffic to a target, whereas harvesting involves offline cracking of captured hashes.

2
MCQeasy

Which of the following describes the primary difference between a Golden Ticket and a Silver Ticket attack in an Active Directory environment?

A.Golden tickets are for NTLM, whereas Silver tickets are for Kerberos.
B.Golden tickets require the KRBTGT hash, while Silver tickets require a service account hash.
C.Silver tickets grant domain admin access, while Golden tickets are restricted to workstations.
D.Only Silver tickets require active communication with the Domain Controller.
AnswerB

Golden tickets require the hash of the KRBTGT account, which allows the forging of TGTs for any resource. Silver tickets require the hash of a specific service account (e.g., MSSQL or CIFS), allowing the forgery of TGS tickets for that specific service, which is much more targeted and quieter.

Why this answer

The distinction between Golden and Silver tickets is fundamental to understanding post-exploitation persistence. Golden tickets involve the KRBTGT account, granting access to the entire domain, while Silver tickets target specific service accounts. Mastering this difference is essential for determining the scope of an attack and the level of stealth required, as Silver tickets are often safer to deploy as they avoid triggering certain domain controller alerts related to TGT requests.

Exam trap

Candidates often believe both tickets provide identical access. However, Golden tickets grant domain-wide persistence via the KRBTGT account, while Silver tickets are limited to specific services, offering less overall control.

3
Multi-Selecthard

You have compromised a domain user account and discovered that the domain controller is running Windows Server 2016. You want to extract the KRBTGT account hash to create a Golden Ticket. Which two conditions are necessary to successfully perform a DCSync attack to obtain the KRBTGT hash? (Choose two.)

Select 2 answers
A.The compromised user account must have the Replicating Directory Changes All permission on the domain object.
B.The compromised account must have the Replicating Directory Changes permission on the domain object.
C.The compromised user account must be a member of the Domain Admins group.
D.The attacker must have local administrator access on the domain controller.
E.The domain functional level must be at least Windows Server 2008 or higher.
AnswersA, B

DCSync abuses the Directory Replication Service (DRS) protocol by impersonating a domain controller. To do so, the account must have the Replicating Directory Changes All extended right on the domain partition, which allows it to request replication of directory data including password hashes. Without this permission, the DRS request will be denied, making this a necessary condition.

Why this answer

To perform DCSync, the compromised account must possess both the Replicating Directory Changes and Replicating Directory Changes All permissions on the domain object. These permissions allow the account to impersonate a domain controller and request replication of directory data, including password hashes. While Domain Admins have these by default, any account with these delegated rights can execute the attack.

Exam trap

The trap here is assuming that Domain Admin membership or local admin access on the DC is required, when in fact only the specific replication permissions are necessary.

4
MCQmedium

You have captured an NTLM hash of a domain user. Why is performing a Pass-the-Hash (PtH) attack often more effective than attempting to crack the hash for the cleartext password?

A.It requires less network traffic than a standard login
B.The hash is accepted directly by the authentication service
C.Cracking the hash is prohibited by corporate policy
D.The hash provides access to all domain controllers
AnswerB

NTLM authentication protocols authenticate using the NTLM hash directly. By providing the hash to the authentication process, the attacker can successfully impersonate the user without needing to crack the hash to reveal the cleartext password, making it an immediate and highly effective method for lateral movement.

Why this answer

Pass-the-Hash relies on the fact that Windows authentication protocols (NTLM) use the hash itself as a form of credential. By injecting the hash into the authentication process, the attacker can authenticate as the user without ever knowing the cleartext password. This bypasses complexity requirements and is immune to password cracking speeds, making it an extremely efficient method for lateral movement within a domain.

Exam trap

Candidates incorrectly believe cracking a hash is necessary to authenticate. In Windows NTLM authentication, the hash itself is treated as the proof of identity, rendering cracking unnecessary for successful login.

5
MCQmedium

You have obtained credentials for a domain user and want to enumerate Active Directory to find misconfigured ACLs that allow privilege escalation. You need to collect data that maps relationships between users, groups, computers, and sessions, and you want to visualize shortest paths to Domain Admin. Which tool and collection method best fits this requirement?

A.Run SharpHound with the -c All collection method and import the resulting JSON files into BloodHound for path analysis.
B.Execute CrackMapExec with the --shares and --sessions modules to enumerate shares and active sessions across the domain.
C.Run ldapsearch against the domain controller with a filter for objectClass=user and parse the output for group membership attributes.
D.Use PowerView's Invoke-ShareFinder to list accessible shares and infer privilege escalation paths from share permissions.
AnswerA

SharpHound is the official BloodHound collector, and the -c All method gathers group memberships, ACLs, sessions, and trusts. The resulting JSON data imports directly into BloodHound, which computes shortest paths to high-value targets like Domain Admin. This combination directly satisfies the requirement to map relationships and visualize escalation paths.

Why this answer

BloodHound with SharpHound is purpose-built for Active Directory attack path analysis. The -c All collection method gathers the full set of relationships, including ACLs and sessions, that BloodHound needs to compute shortest paths. Alternative enumeration tools may gather partial data but lack the graph-based analysis and visualization that makes escalation paths immediately actionable.

Exam trap

The trap here is equating general AD enumeration tools with attack path analysis, when only a graph-based collector and analyzer can compute shortest paths to high-value targets.

6
Multi-Selecthard

Which THREE of the following are valid techniques for achieving persistence within an Active Directory environment?

Select 3 answers
A.Skeleton Key
B.Golden Ticket
C.Kerberoasting
D.AdminSDHolder modification
E.LLMNR Poisoning
AnswersA, B, D

Skeleton Key is an in-memory patch applied to a domain controller that allows any user to authenticate with a master password while still allowing normal password authentication. This provides stealthy, persistent access to any account in the domain without requiring knowledge of the actual user passwords.

Why this answer

Persistence techniques involve creating backdoors that survive account password changes or system reboots. Skeleton Key modifies the LSASS process to accept a master password. Golden Tickets use the KRBTGT hash to forge TGTs indefinitely.

Security Descriptor changes on the 'AdminSDHolder' object ensure that specific permissions are consistently applied to privileged groups, even if an administrator removes them manually, maintaining long-term access.

Exam trap

Candidates often conflate credential dumping with persistence. While tools like Mimikatz extract credentials, persistence requires modifying system objects or services to maintain long-term access after a reboot or password change.

7
MCQmedium

During an internal penetration test you compromise a domain-joined workstation and recover a user's NTLMv2 hash via a forced authentication attempt. SMB signing is enforced on all servers, and the client will not initiate outbound SMB connections. You want to crack the credential offline rather than relay it. Which approach is most appropriate?

A.Use ntlmrelayx.py with the --no-smb-server flag to forward the authentication to a domain controller and dump the SAM database.
B.Use CrackMapExec with the --hash option to spray the netntlmv2 response across the domain and identify where the account is valid.
C.Use Responder in analyze mode to capture the challenge/response, then run Hashcat with mode 5600 against the captured netntlmv2 hash and a targeted wordlist.
D.Run Mimikatz with the sekurlsa::pth module to inject the captured NTLMv2 response into a new logon session and authenticate as the user.
AnswerC

NTLMv2 challenge/response pairs are stored in the netntlmv2 format, which Hashcat mode 5600 is designed to crack. Because SMB signing blocks relay and the client will not initiate outbound SMB, offline cracking is the viable path. Capturing in analyze mode avoids poisoning traffic you cannot use and keeps the evidence clean for the report.

Why this answer

The captured artifact is an NTLMv2 challenge/response, which is only useful for offline cracking. SMB signing prevents relay, and the client's outbound SMB restriction blocks additional capture avenues. Hashcat mode 5600 is the correct cracking mode for netntlmv2, and a targeted wordlist improves efficiency against a real user's password.

Exam trap

The trap here is assuming any captured NTLM material can be relayed or passed directly, when a challenge/response pair requires offline cracking and cannot be used as a hash for authentication.

8
MCQmedium

Which of the following describes the 'GPP Password' vulnerability?

A.A flaw in the Kerberos preauthentication mechanism
B.The storage of cleartext credentials in GPO XML files
C.The inability to enforce password complexity on GPOs
D.A failure in the Domain Controller's LDAP signing
AnswerB

GPP password vulnerability occurs when sensitive credentials stored in Group Policy XML files are encrypted using a publicly available static key. This allows anyone with read access to the SYSVOL share to decrypt the 'cpassword' attribute and obtain the cleartext password, facilitating unauthorized access to local administrator accounts.

Why this answer

Group Policy Preferences (GPP) allows administrators to manage local accounts on domain computers. In older versions of Windows, these passwords were encrypted with a static, publicly known AES key. If an attacker gains read access to the 'Groups.xml' file in the SYSVOL share, they can decrypt the 'cpassword' attribute, revealing the cleartext password of the local administrator account for the affected machine.

Exam trap

Candidates often assume GPP passwords are fully secure because they are encrypted. They overlook that the encryption key is publicly known, making the 'encryption' effectively transparent to any attacker with access.

9
MCQeasy

What is the primary objective of an 'AS-REP Roasting' attack?

A.To capture the KRBTGT hash from the domain controller
B.To crack the password of an account without preauth
C.To bypass the need for an NTLM hash during relay
D.To escalate privileges via a forged Kerberos ticket
AnswerB

AS-REP Roasting exploits accounts with the 'Do not require Kerberos preauthentication' flag. By requesting a ticket without providing preauthentication data, the attacker receives a response encrypted with the user's hash, which can be cracked offline to reveal the cleartext password, regardless of the password's complexity or length.

Why this answer

AS-REP Roasting targets user accounts where Kerberos preauthentication is disabled. By sending an AS-REQ without preauthentication, the domain controller returns an AS-REP containing a TGT encrypted with the user's password hash. The attacker can then extract this hash and perform offline brute-force cracking to recover the user's cleartext password.

This is highly effective against service accounts that have been misconfigured to skip preauthentication.

Exam trap

Candidates often confuse AS-REP Roasting with Kerberoasting. AS-REP Roasting specifically targets accounts where Kerberos preauthentication is disabled, allowing the request of a TGT without knowing the user's password.

10
MCQeasy

Which tool is primarily used to perform BloodHound data collection to map out attack paths within an Active Directory environment?

A.Mimikatz
B.SharpHound
C.Responder
D.PowerSploit
AnswerB

SharpHound is the official data collector for BloodHound. It automates the collection of Active Directory data, including group memberships, ACLs, and session information. This data is essential for building the graph database used in BloodHound to discover and analyze potential attack paths to high-value targets.

Why this answer

BloodHound uses SharpHound as its data collector. SharpHound queries the Active Directory environment to identify relationships between users, groups, computers, and permissions. This data is then imported into the BloodHound graph database, allowing testers to visualize complex attack paths, such as shortest paths to Domain Admin, which would be difficult to identify through manual enumeration alone.

Exam trap

Candidates often confuse the analytical visualization platform name with the actual data gathering executable that runs on the target Active Directory environment.

11
MCQhard

During an internal Active Directory assessment, you have compromised a standard domain user account. You run BloodHound and identify that this user has the 'GenericAll' permission over a computer object named WEB01. You want to leverage this permission to compromise WEB01 and obtain administrative access to it. Which of the following is the most direct and reliable technique to achieve this?

A.Use the GenericAll permission to perform a shadow credentials attack by adding a Key Credential to the msDS-KeyCredentialLink attribute of WEB01.
B.Use the GenericAll permission to perform a targeted Kerberoasting attack by setting an SPN on a user account you control, then request a service ticket.
C.Perform a Kerberoasting attack against the machine account of WEB01 to obtain its hash and then crack it offline.
D.Use the GenericAll permission to perform a resource-based constrained delegation attack by modifying the msDS-AllowedToActOnBehalfOfOtherIdentity attribute.
AnswerA

With GenericAll on a computer object, you can modify the msDS-KeyCredentialLink attribute to add a public key, then authenticate as that computer using PKINIT. This is known as a shadow credentials attack and directly grants you a ticket-granting ticket (TGT) for the machine account, allowing administrative access to WEB01. It is a direct and reliable method.

Why this answer

GenericAll over a computer object allows full control, including modifying the msDS-KeyCredentialLink attribute. By adding a Key Credential, an attacker can authenticate as the computer account via PKINIT and obtain a TGT, effectively taking over the machine. This shadow credentials technique is direct and does not require cracking or additional accounts, making it the most efficient path to compromise WEB01.

Exam trap

The trap here is assuming that GenericAll over a computer object only allows resetting the machine account password or that it must be combined with other misconfigurations, when in fact it directly enables shadow credentials.

12
MCQeasy

Which of the following conditions is required to execute a successful Pass-the-Hash (PtH) attack against a target workstation?

A.The target machine must have Kerberos disabled.
B.The attacker must possess the cleartext password of the target user.
C.The NTLM hash must correspond to an account with local administrative rights.
D.The target machine must be a Domain Controller.
AnswerC

To achieve lateral movement or privilege escalation via PtH, the captured hash must belong to an account that has the necessary permissions on the target system. Without local administrative rights, the attacker may authenticate successfully but will remain restricted to the low-privileged environment of the captured user.

Why this answer

Pass-the-Hash relies on the fact that NTLM authentication uses the hash of a password rather than the password itself. If an attacker gains the NTLM hash of a user who has local administrative rights on a target, they can authenticate as that user. This is a primary method for lateral movement within an AD environment, allowing attackers to escalate privileges across hosts without ever needing to know the user's actual cleartext password.

Exam trap

Candidates often assume that any captured NTLM hash can be used to authenticate against any target. You must specifically possess a hash belonging to an account with local administrative rights on the destination.

13
MCQhard

During a penetration test, you have gained access to a workstation and extracted a Kerberos TGT for a domain user. You want to use this ticket to access a file share on another server without knowing the user's password. Which technique should you employ?

A.Silver Ticket by forging a service ticket for the file share using the service account's hash.
B.Pass-the-Ticket by injecting the TGT into the current session using Mimikatz's kerberos::ptt command.
C.Golden Ticket by forging a TGT using the KRBTGT hash to impersonate any user.
D.Overpass-the-Hash by using the TGT's associated NTLM hash to request a new TGT.
AnswerB

Pass-the-Ticket with Mimikatz's kerberos::ptt injects the extracted TGT into the current logon session, allowing the attacker to impersonate the user for Kerberos authentication. This enables access to network resources like file shares without knowing the password. It is the standard method for leveraging stolen Kerberos tickets in Active Directory environments.

Why this answer

Pass-the-Ticket with Mimikatz's kerberos::ptt injects the stolen TGT into the current session, allowing Kerberos authentication as the user. This grants access to network resources such as file shares without needing the password. It is the appropriate technique when a TGT is already available and the goal is to use it for lateral movement.

Exam trap

The trap here is confusing Pass-the-Ticket with other Kerberos attacks like Overpass-the-Hash or Golden Ticket, which require different prerequisites such as hashes or elevated privileges.

14
MCQmedium

You have compromised a domain user account and want to escalate privileges by abusing a misconfigured Group Policy Object (GPO). You discover that the GPO is linked to an Organizational Unit (OU) containing privileged servers and that the domain user has write permissions on the GPO. Which action should you take to escalate privileges?

A.Use the compromised user to add themselves to the Domain Admins group directly via LDAP modification.
B.Configure a new GPO to deploy a startup script that disables antivirus on all servers in the OU.
C.Extract the KRBTGT hash using DCSync and forge a Golden Ticket to gain domain admin access.
D.Modify the GPO to add a new immediate scheduled task that runs a reverse shell as SYSTEM on all computers in the OU.
AnswerD

If a user has write permissions on a GPO linked to an OU with privileged servers, they can modify the GPO to include a malicious scheduled task or startup script. This task will execute with SYSTEM privileges on all affected computers when Group Policy refreshes. This is a direct and effective privilege escalation method, as it leverages the GPO's application to gain elevated code execution.

Why this answer

With write permissions on a GPO linked to an OU containing privileged servers, modifying the GPO to add an immediate scheduled task that runs as SYSTEM allows code execution with elevated privileges on those servers. This directly escalates privileges by leveraging the GPO's application to all computers in the OU, achieving SYSTEM-level access.

Exam trap

The trap here is assuming that write access to a GPO allows direct domain admin escalation, when in fact it enables code execution as SYSTEM on affected machines, which can then be used for further privilege escalation.

15
MCQmedium

You have obtained a low-privileged domain user account and are performing internal enumeration. You identify a computer object in the domain where the 'ms-MCS-AdmPwd' attribute is readable by your user account. Which attack path does this vulnerability facilitate?

A.Kerberoasting the computer account password hash
B.Exploiting the GPO to modify the Domain Admins group
C.Extracting the cleartext local administrator password
D.Performing an AS-REP Roasting attack on the machine
AnswerC

The LAPS solution stores the cleartext local administrator password in the ms-MCS-AdmPwd attribute of the computer object. If a domain user has read access to this attribute, they can retrieve the password, enabling them to authenticate as the local administrator on that specific computer, facilitating unauthorized access.

Why this answer

The ms-MCS-AdmPwd attribute stores the cleartext Local Administrator Password for a computer managed by LAPS. By reading this attribute, an attacker can extract the password for the local administrator account of the target machine. This is a critical discovery because it allows immediate lateral movement from a low-privileged domain context to local administrative privileges on that specific host, potentially leading to further credential harvesting or domain escalation.

Exam trap

Students often misidentify LAPS attribute names or confuse computer object permissions with standard user right assignments, missing the direct implications of readable administrative passwords.

16
MCQhard

Why does enabling 'SMB Signing' prevent NTLM relay attacks?

A.It encrypts the entire SMB session using TLS
B.It requires the client to prove they have the password
C.It validates the integrity of the authentication packets
D.It disables NTLM authentication globally
AnswerC

SMB signing forces the use of cryptographic signatures for every packet. Because the attacker cannot generate valid signatures for the relayed authentication without the session key, the target server rejects the relayed packets. This makes it impossible to relay authentication successfully between a client and a target server.

Why this answer

SMB Signing adds a cryptographic signature to each packet in an SMB communication. When a relay attack occurs, the attacker does not possess the session key required to generate these signatures for the relayed packets. Consequently, the target server detects the missing or invalid signature and rejects the authentication attempt, effectively neutering the relay attack at the protocol level.

Exam trap

Candidates often assume SMB signing encrypts the entire traffic flow. In reality, it only adds a cryptographic signature to each packet to verify its integrity and origin, preventing unauthorized relaying.

17
MCQmedium

During an internal assessment you compromise a workstation and recover a Kerberos TGS ticket from memory that belongs to a service account. Analysis shows the ticket was encrypted with the RC4-HMAC cipher using a key derived from the service account's password hash. You want to recover the plaintext password of that service account offline. Which action should you take?

A.Submit the ticket to the domain controller with GetUserSPNs.py and let the KDC decrypt it to disclose the service account's NT hash.
B.Convert the ticket to a .kirbi file and import it with Rubeus to request a service ticket that reveals the account password in the response.
C.Use Kerbrute to spray the recovered ticket against the domain controller and read the resulting authentication error codes.
D.Crack the ticket offline with Hashcat in mode 13100, since the ticket is encrypted with RC4-HMAC and its checksum can be attacked with a wordlist.
AnswerD

A TGS-REP ticket encrypted with RC4-HMAC can be brute-forced offline because the checksum is keyed by the service account's NT hash. Hashcat mode 13100 targets Kerberos 5 TGS-REP etype 23 hashes exactly, allowing a wordlist or rule-based attack to recover the plaintext, which is the standard Kerberoasting cracking path.

Why this answer

A service ticket encrypted with RC4-HMAC (etype 23) is protected by a key derived from the target service account's NT hash, so the ciphertext can be attacked entirely offline. Extracting the TGS-REP hash and running Hashcat mode 13100 against a wordlist recovers the plaintext password when it is weak, without generating additional authentication traffic against the domain.

Exam trap

The trap here is assuming a captured service ticket can be replayed to the KDC to reveal the password, when in fact Kerberoasting success depends on cracking the RC4-encrypted ticket offline.

18
MCQmedium

During an internal assessment, you compromise a workstation and recover a cached domain credential hash for a user who previously logged on. You want to use this hash to authenticate to a file server on the same network, but you do not know the plaintext password. Which of the following tools is specifically designed to perform Pass-the-Hash authentication from a Linux-based attack platform?

A.Hashcat with mode 1000
B.Responder with the -w flag
C.Mimikatz with the sekurlsa::logonpasswords module
D.Impacket's psexec.py
AnswerD

Impacket's psexec.py supports Pass-the-Hash via the -hashes argument, allowing an attacker to authenticate to SMB services using an NTLM hash without knowing the plaintext password. It constructs the SMB session using the provided LM:NT hash pair, which is precisely the objective in this scenario where only the hash was recovered from a compromised workstation.

Why this answer

Pass-the-Hash requires a tool that can supply an NTLM hash directly during authentication. Impacket's psexec.py is a Python implementation of PsExec that accepts -hashes, enabling authentication to SMB shares with a hash. The other tools either crack hashes offline, harvest credentials, or extract credentials locally, none of which achieve remote authentication with a hash.

Exam trap

The trap here is assuming that any credential extraction tool like Mimikatz or Hashcat can also perform Pass-the-Hash authentication, when in fact only specific modules or tools are designed for that purpose.

19
MCQmedium

When performing a DCSync attack, what is the core mechanism being exploited?

A.The Kerberos ticket granting service process
B.The Active Directory Replication Service (DRS) protocol
C.The LDAP signing enforcement on the Domain Controller
D.The storage of passwords in the SYSVOL share
AnswerB

DCSync uses the DRS protocol to request that a domain controller send account data, including password hashes, as if it were performing a legitimate replication operation. This allows an attacker to dump credentials for any user in the domain without ever needing to log into the domain controller itself.

Why this answer

DCSync exploits the Active Directory replication protocol. By mimicking the behavior of a domain controller, an attacker can request that another domain controller replicate user credentials, including password hashes, to them. This requires the attacker to hold 'Replication-Get-Changes' and 'Replication-Get-Changes-All' permissions, which are typically only held by domain controllers or highly privileged administrators, making it a powerful tool for dumping the entire domain's secrets.

Exam trap

Candidates often confuse DCSync with standard credential dumping from memory. DCSync specifically targets the replication protocol to pull secrets directly from a Domain Controller, not from a local workstation's memory.

20
Multi-Selecthard

You have compromised a service account that has the SeEnableDelegationPrivilege right on a domain controller. You want to abuse Kerberos delegation to gain access to a target server's file share. Which two steps are required to configure and exploit unconstrained delegation on a controlled computer object? (Choose two.)

Select 2 answers
A.Configure a Service Principal Name on the controlled computer object for the target file share service (cifs/target).
B.Set the TRUSTED_FOR_DELEGATION flag on the controlled computer object so the domain controller will forward TGTs to it.
C.Modify the msDS-AllowedToDelegateTo attribute on the controlled computer to include the target server's CIFS service.
D.Add the controlled computer to the Protected Users group to ensure delegation tokens are cached securely.
E.Coerce a privileged user to authenticate to the controlled computer so its TGT is captured in memory and can be extracted.
AnswersB, E

Unconstrained delegation requires the TRUSTED_FOR_DELEGATION userAccountControl flag on the computer object. With SeEnableDelegationPrivilege, you can set this flag on a machine you control. The domain controller then includes that computer in the list of services allowed to receive forwarded TGTs, which is the foundational configuration for this attack.

Why this answer

Unconstrained delegation abuse requires two things: enabling the TRUSTED_FOR_DELEGATION flag on a controlled computer so the DC forwards TGTs to it, and coercing a privileged user to authenticate to that computer so a TGT is cached in memory. Extracting the TGT then allows impersonation. The other options describe constrained delegation, an unrelated SPN configuration, or a security control that blocks the attack.

Exam trap

The trap here is confusing unconstrained delegation, which relies on the TRUSTED_FOR_DELEGATION flag and TGT capture, with constrained delegation, which uses msDS-AllowedToDelegateTo and SPNs.

21
MCQeasy

You have obtained a plaintext password for a domain user and want to quickly identify which domain-joined systems the account can access with local administrative rights, without triggering account lockout. Which approach is most appropriate?

A.Use CrackMapExec with the -u and -p options against a list of hosts and the smb module to check for administrative access.
B.Execute BloodHound with SharpHound using the -c Session collection method to enumerate where the user has administrative rights.
C.Use Hydra to brute-force the password against SMB on each host to confirm administrative access.
D.Run Responder on the network to poison LLMNR and capture administrative credentials from other hosts.
AnswerA

CrackMapExec's smb module with valid credentials performs a single authentication attempt per host, checking for administrative access without repeated failed logons. This avoids lockout because it uses the correct password and does not spray. It efficiently identifies which systems grant local admin rights to the compromised account.

Why this answer

CrackMapExec with valid credentials is the standard tool for quickly checking administrative access across many hosts. It performs a single authentication per host using the known password, avoiding lockout, and reports whether the account has local admin rights. Alternatives either risk lockout, capture unrelated credentials, or collect session data that does not directly answer the access question.

Exam trap

The trap here is assuming that brute-forcing or password spraying is needed to test access, when valid credentials should be used directly to avoid lockout and unnecessary noise.

22
Multi-Selecthard

During an Active Directory penetration test, you have obtained Domain Admin privileges. To maintain persistent access, you decide to create a Golden Ticket. Which two of the following pieces of information are required to forge a valid Golden Ticket? (Choose two.)

Select 2 answers
A.The target user's password.
B.The KRBTGT account's NTLM hash.
C.A valid Kerberos TGT for a Domain Admin.
D.The Domain Controller's machine account hash.
E.The domain's SID.
AnswersB, E

The KRBTGT account's NTLM hash is used to encrypt and sign the Golden Ticket. Without it, the ticket cannot be forged because the KDC uses this hash to validate TGTs. This is a core requirement for creating a Golden Ticket, as it allows the attacker to mint TGTs for any user, including Domain Admins.

Why this answer

To forge a Golden Ticket, you need the KRBTGT account's NTLM hash to encrypt the ticket and the domain SID to populate the PAC correctly. These two elements allow you to create a TGT for any user, granting persistent domain-wide access. Other items like a valid TGT or user passwords are not required, as the ticket is self-signed with the KRBTGT hash.

Exam trap

The trap here is thinking that a Golden Ticket requires a legitimate TGT or user password, when in fact it is forged using the KRBTGT hash and domain SID.

Ready to test yourself?

Try a timed practice session using only Active Directory Attacks questions.