ACL in Active Directory & LDAP Flashcards
6 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 ACL in Active Directory & LDAP flashcards as text
Which built-in Windows tool automates the process of assigning ACL-based delegated permissions on Active Directory OUs?
Answer: Delegation of Control Wizard in ADUC
The Delegation of Control Wizard in ADUC simplifies assigning specific administrative permissions to users or groups on an OU, guiding admins through common delegation scenarios.
What does the 'GenericAll' ACE represent in Active Directory?
Answer: Full control permission granting all rights over an AD object
GenericAll is the most powerful ACE in Active Directory, granting complete control over an object including modifying attributes, resetting passwords, and changing the object's ACL.
What is a common Active Directory attack technique that exploits misconfigured ACLs?
Answer: ACL abuse using overpermissioned ACEs like WriteDACL or GenericAll to escalate privileges
ACL abuse exploits overly permissive ACEs (such as WriteDACL, GenericWrite, or GenericAll) to escalate privileges or take control of accounts in Active Directory.
What does the 'WriteDACL' permission allow an attacker to do in Active Directory?
Answer: Modify the DACL of an object to grant themselves additional permissions
WriteDACL allows a principal to modify an object's DACL, enabling an attacker to grant themselves additional rights such as Full Control over that object.
In OpenLDAP ACL syntax, what does the 'by' clause specify?
Answer: Who the access rule applies to, such as specific users, authenticated users, or anonymous connections
The 'by' clause in an OpenLDAP ACL defines who the permission applies to, supporting specifiers like `users`, `anonymous`, `self`, or specific DNs.
What is the purpose of the 'Protected Users' security group in Active Directory?
Answer: Applies authentication restrictions to reduce credential theft exposure for sensitive accounts
Accounts in the Protected Users group cannot use NTLM, DES, or RC4 Kerberos encryption, and credentials are not cached, significantly reducing the attack surface for credential-based attacks.