Exercises
Assess your ability to secure Microsoft Active Directory environments against common identity-based attacks. This quiz covers domain controllers, Kerberos, NTLM, privileged groups, delegation, service accounts, DCSync, Golden Tickets, Active Directory Certificate Services, Group Policy, event monitoring, trust relationships, and directory recovery. Questions combine foundational concepts with practical attack recognition and defensive controls.
Answer the questions below and check the explanation for each answer.
0/20 answered
Auto audio on: the next questions will be read aloud when you click Continue.
A domain controller authenticates users and computers, stores Active Directory data, and helps enforce domain security policies. It is not a replacement for a firewall or endpoint encryption.
The Authentication Service, part of the Key Distribution Center, validates the initial request and issues a Ticket Granting Ticket. The TGT is later presented to the Ticket Granting Service.
Role-specific delegation grants administrators only the permissions needed for their duties. Permanent broad privileges increase the impact of account misuse or compromise.
Signing in to a lower-trust device can expose privileged credentials or session material to malware. Administrative tiering keeps highly privileged accounts away from ordinary workstations.
Windows LAPS manages unique, regularly rotated local administrator passwords for enrolled devices. This limits lateral movement that relies on a shared local credential.
Kerberoasting obtains Kerberos service tickets whose encrypted portions can be tested offline against password guesses. Service accounts with weak passwords are especially vulnerable.
LDAP signing provides integrity protection by requiring signed LDAP sessions. It reduces exposure to manipulation and some man-in-the-middle or relay scenarios involving unsigned binds.
Constrained delegation limits impersonation to explicitly authorized services. Unconstrained delegation exposes credentials more broadly and creates greater risk if the delegated server is compromised.
A group Managed Service Account uses a complex password managed and rotated by Active Directory. Authorized systems retrieve it automatically, reducing manual password handling and stale credentials.
When Kerberos preauthentication is disabled, an attacker can request authentication response data for the account without first proving knowledge of its password, enabling offline password guessing.
Pass-the-hash uses an obtained NTLM hash to authenticate without recovering the original plaintext password. Restricting NTLM and protecting credential material help reduce this risk.
DCSync abuses directory replication permissions to imitate a domain controller and request sensitive account data. Replication rights must be tightly restricted and monitored.
The KRBTGT account secret protects domain Ticket Granting Tickets. If compromised, it can be used to forge TGTs. Recovery generally requires two carefully planned KRBTGT password resets.
Protected Users receive additional safeguards, including blocking NTLM authentication and restricting credential caching and delegation. Compatibility should be tested before adding accounts.
This combination is associated with an AD CS ESC1-style misconfiguration. A low-privileged enrollee may place another identity in the certificate and use it for authentication.
Event ID 4769 records requests for Kerberos service tickets. Unusual request volume, uncommon services, weak encryption types, or unexpected requesting hosts can support investigation.
If Domain A trusts Domain B, A accepts authentication claims for B's users. Those users may therefore be authorized to access resources in A, subject to assigned permissions.
An authoritative restore marks selected restored directory objects as authoritative so they replicate to other domain controllers. A non-authoritative restore instead receives newer directory data from replication partners.
Computer configuration settings are processed by computer objects within the linked scope. Inheritance, enforced links, blocking, security filtering, and WMI filters can alter final application.
A domain controller compromise is a high-impact identity incident. Coordinated containment, evidence preservation, scope analysis, credential remediation, and recovery planning are safer than unplanned destructive actions.

Free CourseFoundations of Cryptography: Symmetric, Public-Key, Hashing and Signatures
32h51m
57 exercises

Free CourseAdvanced Topics in Cryptography
22h34m
9 exercises

Free CourseInformation Security Management Fundamentals
2h55m
15 exercises

Free CourseComputer systems security
29h44m
20 exercises

Free CourseIT Security
15h04m
18 exercises

Free CourseCyber security
2h07m
24 exercises

Free CourseInformation security lessons
7h15m
11 exercises

Free CourseCyber Security Masterclass
1h36m
6 exercises
Thousands of online courses in video, ebooks and audiobooks.
To test your knowledge during online courses
Generated directly from your cell phone's photo gallery and sent to your email
Download our app via QR Code or the links below:.
+ 10 million
students
Free and Valid
Certificate
60 thousand free
exercises
4.8/5 rating in
app stores
Free courses in
video and ebooks