A penetration test demonstrates that an attacker can use DCSync to extract all password hashes from the domain without logging into a DC. Which AD permission grants this capability?
-
A
Write permission on the domain's AdminSDHolder object
-
B
Replicating Directory Changes All permission on the domain naming context
-
C
Manage Auditing and Security Log permission on the domain root
-
D
Full Control on the Domain Controllers OU