Courseiva

PEN-200 · topic practice

Active Directory Attacks practice questions

This domain covers post-compromise Active Directory tradecraft on Windows estates: enumerating ACLs and delegation with BloodHound and PowerView, abusing Kerberos (Kerberoasting, AS-REP roasting, delegation, DCSync), and pivoting from a standard user to Domain Admin. Questions test tool selection, attack mechanics, and required privileges rather than raw exploitation steps.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Active Directory Attacks

What the exam tests

What to know about Active Directory Attacks

You must chain enumeration to exploitation: read BloodHound/PowerView output, pick the correct ACL or delegation abuse, and execute it with Mimikatz, Impacket, or NetExec. The critical thing is verifying the exact privilege a technique requires before running it, so you avoid lockouts and access-denied failures.

Reading BloodHound edges like GenericAll, WriteDACL, and ForceChangePassword to plan ACL abuse paths

Executing DCSync with Mimikatz lsadump::dcsync or Impacket secretsdump against a domain controller

Abusing Kerberos delegation: unconstrained, constrained, and resource-based constrained delegation with SeEnableDelegationPrivilege

Enumerating accessible systems with CrackMapExec or NetExec smb using the compromised credential safely

Watch out for

Common Active Directory Attacks exam traps

  • ▸Confusing GenericAll on a computer object with local admin: it grants object control, so you must still add a computer account or reset the machine password to get a shell.
  • ▸Running DCSync without Replicating Directory Changes and Replicating Directory Changes All rights, or from an account lacking them, causing access denied.
  • ▸Triggering account lockout by spraying the plaintext password across many hosts instead of checking one host or using a lockout-aware tool.

Practice set

Active Directory Attacks questions

20 questions · select your answer, then reveal the explanation

When assessing Active Directory, which TWO of the following configurations are considered high-risk misconfigurations that commonly lead to full domain compromise?

In an Active Directory environment, what is the primary security risk associated with the 'Account is sensitive and cannot be delegated' attribute on a user account?

You have compromised a low-privilege user account in an Active Directory forest. After enumerating the domain, you identify that the 'Pre-Windows 2000 Compatible Access' group contains the 'Authenticated Users' group. Which attack vector is most directly facilitated by this specific misconfiguration?

You have gained local administrator access to a workstation where a Domain Admin recently logged in. You suspect the user's credentials may be cached in memory. Which TWO techniques would allow you to extract these credentials from the LSASS process?

You are performing a domain enumeration and want to identify potential pathways to escalate privileges using GPO-based misconfigurations. Which THREE of the following conditions might indicate a GPO that can be abused for privilege escalation?

You have discovered a user account that has 'GenericWrite' access to a Domain Admin account. How can you leverage this permission to achieve domain compromise?

When performing a Kerberoasting attack, why is it preferable to target accounts with high privilege levels or service accounts with long, complex names?

You have obtained Domain Admin credentials in a Windows Active Directory environment. You want to establish long-term persistence that survives password changes of the compromised account. Which of the following techniques should you use?

You have obtained domain user credentials for 'jsmith' and are enumerating the Active Directory environment from a compromised Windows 10 workstation. You want to identify domain computers where unconstrained Kerberos delegation is enabled, because these systems can cache TGTs of any authenticating user. Which native Windows utility should you run to query this information?

During an internal assessment, you have obtained credentials for a standard domain user, jsmith, and have a foothold on a workstation. You want to identify domain-joined systems where jsmith has local administrator rights without triggering alerts from traditional port scanning. Which approach best accomplishes this while minimizing network noise?

Question 11hardmultiple choice
Study the full ACL explanation →

You have administrative access to a workstation in a domain where you previously collected BloodHound data. The data shows an ACL edge indicating your current user has GenericAll over a target user object, but you have no idea what the target user's password is. You want to leverage this ACL to obtain access to resources the target user can reach. Which technique should you perform?

During an internal penetration test, you have compromised a workstation and extracted the NTLM hash of a service account. You attempt a Pass-the-Hash attack but receive an 'Access Denied' error. You confirm the hash is correct and the account has local admin rights on the target. What is the most likely reason for the failure?

You are on an internal engagement and have obtained the NTLM hash of a service account that has local administrator rights on several member servers. SMB signing is not enforced on those servers. You want to gain interactive access to one server without cracking the hash. Which approach best fits this situation?

You have obtained the NTLM hash of a service account that is used to run a scheduled task on multiple servers. You want to use this hash to authenticate to those servers and execute commands without knowing the plaintext password. Which tool and technique should you use to achieve this with the least effort?

During an Active Directory assessment you have domain user credentials and want to enumerate misconfigurations that could allow privilege escalation. You plan to use PowerView for this. Which TWO cmdlets would directly help you identify accounts configured with unconstrained delegation? (Choose two.)

You have compromised a domain user account and are looking to escalate privileges. You discover that the domain has a Group Policy Object (GPO) that grants the 'SeEnableDelegationPrivilege' to a non-privileged group called 'Helpdesk'. What is the most direct way to abuse this misconfiguration to gain domain admin equivalent access?

You are performing an Active Directory assessment and have gained access to a domain-joined Windows workstation as a low-privileged user. You want to quickly identify all Kerberoastable accounts in the domain. Which command-line tool is specifically designed for this purpose and is commonly used in OSCP-like environments?

You have obtained a low-privileged domain user account and are performing internal enumeration. You identify a computer object in the domain where the 'ms-MCS-AdmPwd' attribute is readable by your user account. Which attack path does this vulnerability facilitate?

Which tool is primarily used to perform BloodHound data collection to map out attack paths within an Active Directory environment?

Which THREE of the following are valid techniques for achieving persistence within an Active Directory environment?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Active Directory Attacks sessions

Start a Active Directory Attacks only practice session

Every question in these sessions is drawn from the Active Directory Attacks domain — nothing else.

Related practice questions

Related PEN-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PEN-200 exam test about Active Directory Attacks?
You must chain enumeration to exploitation: read BloodHound/PowerView output, pick the correct ACL or delegation abuse, and execute it with Mimikatz, Impacket, or NetExec. The critical thing is verifying the exact privilege a technique requires before running it, so you avoid lockouts and access-denied failures.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Active Directory Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Active Directory Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PEN-200 topics?
Use the topic links above to move to related areas, or go back to the PEN-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PEN-200 exam covers. They are not copied from any real exam or dump site.