Courseiva
Active Directory Attacks →mediumMultiple Choice

PEN-200 Active Directory Attacks Practice Question

You have obtained credentials for a domain user and want to enumerate Active Directory to find misconfigured ACLs that allow privilege escalation. You need to collect data that maps relationships between users, groups, computers, and sessions, and you want to visualize shortest paths to Domain Admin. Which tool and collection method best fits this requirement?

⚠ Common exam trap

The trap here is equating general AD enumeration tools with attack path analysis, when only a graph-based collector and analyzer can compute shortest paths to high-value targets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run SharpHound with the -c All collection method and import the resulting JSON files into BloodHound for path analysis.

BloodHound with SharpHound is purpose-built for Active Directory attack path analysis. The -c All collection method gathers the full set of relationships, including ACLs and sessions, that BloodHound needs to compute shortest paths. Alternative enumeration tools may gather partial data but lack the graph-based analysis and visualization that makes escalation paths immediately actionable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run SharpHound with the -c All collection method and import the resulting JSON files into BloodHound for path analysis.

    Why this is correct

    SharpHound is the official BloodHound collector, and the -c All method gathers group memberships, ACLs, sessions, and trusts. The resulting JSON data imports directly into BloodHound, which computes shortest paths to high-value targets like Domain Admin. This combination directly satisfies the requirement to map relationships and visualize escalation paths.

  • ✗

    Execute CrackMapExec with the --shares and --sessions modules to enumerate shares and active sessions across the domain.

    Why it's wrong here

    CrackMapExec's --shares and --sessions modules gather share listings and logged-on sessions, which are useful for lateral movement planning. However, they do not collect ACL data or build a relationship graph. Without ACL and trust data, no shortest-path analysis to Domain Admin is possible from this output alone.

  • ✗

    Run ldapsearch against the domain controller with a filter for objectClass=user and parse the output for group membership attributes.

    Why it's wrong here

    ldapsearch can retrieve user objects and group memberships, but it does not collect ACLs, sessions, or trust relationships in a format that supports graph analysis. Parsing raw LDAP output manually is slow and error-prone. It also lacks the visualization and shortest-path computation that BloodHound provides.

  • ✗

    Use PowerView's Invoke-ShareFinder to list accessible shares and infer privilege escalation paths from share permissions.

    Why it's wrong here

    Invoke-ShareFinder enumerates SMB shares and their access rights, which can reveal sensitive files but does not map ACL relationships or compute attack paths. It is a discovery tool, not a graph-based path analyzer. It cannot produce the relationship map or shortest-path visualization the scenario requires.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.