Exercises

Securing Microsoft Active Directory: Identity Attacks and Defenses

Assess your ability to secure Microsoft Active Directory environments against common identity-based attacks. This quiz covers domain controllers, Kerberos, NTLM, privileged groups, delegation, service accounts, DCSync, Golden Tickets, Active Directory Certificate Services, Group Policy, event monitoring, trust relationships, and directory recovery. Questions combine foundational concepts with practical attack recognition and defensive controls.

Answer the questions below and check the explanation for each answer.

0/20 answered

  1. 1

    In the illustrated domain environment, what is the primary security function of the highlighted domain controller?

    Question 1
  2. 2

    Which Kerberos component issues a Ticket Granting Ticket after validating a user's initial authentication request?

  3. 3

    Which administrative practice best applies the principle of least privilege in Active Directory?

  4. 4

    The diagram shows a Tier 0 administrator signing in to a standard employee workstation. What is the principal security risk?

    Question 4
  5. 5

    What security problem does Windows Local Administrator Password Solution primarily address?

  6. 6

    The illustrated activity shows an account requesting service tickets for several service principal names and exporting ticket data for offline processing. Which attack does this represent?

    Question 6
  7. 7

    What is the main purpose of requiring LDAP signing on domain controllers?

  8. 8

    In the diagram, a front-end server may impersonate users only when connecting to one approved database service. Which delegation model is shown?

    Question 8
  9. 9

    Which feature is a key security benefit of a group Managed Service Account?

  10. 10

    Which account configuration is required for a conventional AS-REP roasting attack?

  11. 11

    What credential material is commonly reused during a pass-the-hash attack against Windows systems?

  12. 12

    The diagram shows a non-domain-controller account requesting directory replication data, including password-related attributes. Which attack technique is depicted?

    Question 12
  13. 13

    Compromise of which account secret enables an attacker to forge Golden Tickets for an Active Directory domain?

  14. 14

    Which authentication behavior applies to members of the Active Directory Protected Users group on supported systems?

  15. 15

    The certificate template shown permits broad enrollment, client authentication, and requester-supplied subject names. Why is this configuration dangerous?

    Question 15
  16. 16

    Which Windows security event ID records a Kerberos service ticket request and can help identify Kerberoasting activity?

  17. 17

    The diagram states that Domain A trusts Domain B through a one-way trust. Which users may be granted access to resources in Domain A?

    Question 17
  18. 18

    Which Active Directory recovery procedure marks restored objects so their versions replicate outward and replace deleted copies on other domain controllers?

  19. 19

    The diagram shows a security Group Policy Object linked to an organizational unit containing computer accounts. Where will its computer configuration settings normally apply?

    Question 19
  20. 20

    What is the most appropriate initial approach after credible evidence indicates that a domain controller has been compromised?

Download the App now to have access to + 5000 free courses, exercises, certificates and lots of content without paying anything!

  • 100% free online courses from start to finish

    Thousands of online courses in video, ebooks and audiobooks.

  • More than 60 thousand free exercises

    To test your knowledge during online courses

  • Valid free Digital Certificate with QR Code

    Generated directly from your cell phone's photo gallery and sent to your email

Cursa app on the ebook screen, the video course screen and the course exercises screen, plus the course completion certificate