PEN-200 Active Directory Attacks Practice Question
Which THREE of the following are valid techniques for achieving persistence within an Active Directory environment?
⚠ Common exam trap
Candidates often conflate credential dumping with persistence. While tools like Mimikatz extract credentials, persistence requires modifying system objects or services to maintain long-term access after a reboot or password change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Skeleton Key
Persistence techniques involve creating backdoors that survive account password changes or system reboots. Skeleton Key modifies the LSASS process to accept a master password. Golden Tickets use the KRBTGT hash to forge TGTs indefinitely. Security Descriptor changes on the 'AdminSDHolder' object ensure that specific permissions are consistently applied to privileged groups, even if an administrator removes them manually, maintaining long-term access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Skeleton Key
Why this is correct
Skeleton Key is an in-memory patch applied to a domain controller that allows any user to authenticate with a master password while still allowing normal password authentication. This provides stealthy, persistent access to any account in the domain without requiring knowledge of the actual user passwords.
- ✓
Golden Ticket
Why this is correct
A Golden Ticket is a forged TGT created using the KRBTGT account's NTLM hash. Because it does not rely on real account passwords, it can be configured with an extremely long expiration date, allowing an attacker to maintain persistent, high-level access to the domain as long as the KRBTGT hash remains unchanged.
- ✗
Kerberoasting
Why it's wrong here
Kerberoasting is an initial access or privilege escalation technique used to extract password hashes for offline cracking. It is not a persistence mechanism, as it does not inherently provide a way to regain access to the domain after the current session ends or if the account password is changed.
- ✓
AdminSDHolder modification
Why this is correct
Modifying the ACLs on the AdminSDHolder object ensures that any changes to permissions are automatically propagated to protected groups and accounts within the domain. By adding a backdoored user or group to the ACL, an attacker ensures their access persists even after an administrator cleans up other unauthorized changes.
- ✗
LLMNR Poisoning
Why it's wrong here
LLMNR poisoning is a technique used to capture network traffic and NTLMv2 hashes. It relies on the local network broadcast environment and is an opportunistic attack vector. It cannot be used to establish long-term persistence in Active Directory, as it does not grant the attacker continuous, reliable authentication capabilities.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.