Risk Assessment & Management Flashcards
7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
A penetration test demonstrates that an attacker can use DCSync to extract all password hashes from the domain without logging into a DC. Which AD permission grants this capability?
Answer: Replicating Directory Changes All permission on the domain naming context
The 'Replicating Directory Changes All' extended right allows any account to request replication of all attribute data including password hashes via DCSync.
Your risk management framework requires periodic attestation that privileged group memberships are still authorized. Which built-in Windows Server 2008 R2 feature supports this process?
Answer: Audit account management events and generate periodic membership reports from Security logs
Auditing account management events and exporting Security log data provides a record of membership changes that can be reviewed periodically for attestation purposes.
A risk review finds that the AdminSDHolder object has been modified to grant a non-privileged group full control, which propagates to all protected accounts. How should this be remediated?
Answer: Remove the unauthorized ACE from AdminSDHolder and run SDProp immediately using 'repadmin /syncall'
Removing the unauthorized ACE from AdminSDHolder and triggering the SDProp process (via FixUpInheritance registry key or restarting the KDC) propagates the corrected ACL to all protected accounts.
During a risk assessment, you determine that delegated OUs allow OU admins to reset the password of Domain Admins accounts within their OU. Which mechanism prevents this privilege escalation?
Answer: Enable AdminSDHolder protection, which overrides explicit delegation ACEs on protected accounts
AdminSDHolder protection automatically overwrites ACEs on privileged account objects every 60 minutes, removing delegated permissions that could allow OU admins to reset privileged passwords.
A compliance requirement mandates that all failed authentication attempts against the domain be logged with source IP addresses. Which setting captures this information in Windows Server 2008?
Answer: Enable Advanced Audit Policy 'Audit Credential Validation' on domain controllers
The Advanced Audit Policy subcategory 'Audit Credential Validation' on domain controllers logs event 4776 for NTLM and captures source workstation information for failed authentications.
Your organization needs to assess the blast radius if the Enterprise Admins group is compromised. Which AD objects would be directly affected?
Answer: All domains in the forest, including schema, configuration, and all domain partitions
Enterprise Admins have full control over all domains in the Active Directory forest, including the schema, configuration partition, and all domain naming contexts.
A risk mitigation plan requires that certificate templates in Active Directory Certificate Services cannot be modified by domain users to enable certificate-based privilege escalation (ESC1). Which control prevents this?
Answer: Disable the 'Supply in the request' subject name option and remove overly permissive enrollment ACLs from sensitive templates
Disabling 'Supply in the request' on certificate templates and restricting enrollment to authorized groups prevents the ESC1 attack where users request certificates with arbitrary SANs for privilege escalation.