PEN-200 Active Directory Attacks Practice Question
You have obtained credentials for a domain user and want to enumerate Active Directory to find misconfigured ACLs that allow privilege escalation. You need to collect data that maps relationships between users, groups, computers, and sessions, and you want to visualize shortest paths to Domain Admin. Which tool and collection method best fits this requirement?
⚠ Common exam trap
The trap here is equating general AD enumeration tools with attack path analysis, when only a graph-based collector and analyzer can compute shortest paths to high-value targets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run SharpHound with the -c All collection method and import the resulting JSON files into BloodHound for path analysis.
BloodHound with SharpHound is purpose-built for Active Directory attack path analysis. The -c All collection method gathers the full set of relationships, including ACLs and sessions, that BloodHound needs to compute shortest paths. Alternative enumeration tools may gather partial data but lack the graph-based analysis and visualization that makes escalation paths immediately actionable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run SharpHound with the -c All collection method and import the resulting JSON files into BloodHound for path analysis.
Why this is correct
SharpHound is the official BloodHound collector, and the -c All method gathers group memberships, ACLs, sessions, and trusts. The resulting JSON data imports directly into BloodHound, which computes shortest paths to high-value targets like Domain Admin. This combination directly satisfies the requirement to map relationships and visualize escalation paths.
- ✗
Execute CrackMapExec with the --shares and --sessions modules to enumerate shares and active sessions across the domain.
Why it's wrong here
CrackMapExec's --shares and --sessions modules gather share listings and logged-on sessions, which are useful for lateral movement planning. However, they do not collect ACL data or build a relationship graph. Without ACL and trust data, no shortest-path analysis to Domain Admin is possible from this output alone.
- ✗
Run ldapsearch against the domain controller with a filter for objectClass=user and parse the output for group membership attributes.
Why it's wrong here
ldapsearch can retrieve user objects and group memberships, but it does not collect ACLs, sessions, or trust relationships in a format that supports graph analysis. Parsing raw LDAP output manually is slow and error-prone. It also lacks the visualization and shortest-path computation that BloodHound provides.
- ✗
Use PowerView's Invoke-ShareFinder to list accessible shares and infer privilege escalation paths from share permissions.
Why it's wrong here
Invoke-ShareFinder enumerates SMB shares and their access rights, which can reveal sensitive files but does not map ACL relationships or compute attack paths. It is a discovery tool, not a graph-based path analyzer. It cannot produce the relationship map or shortest-path visualization the scenario requires.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.