โ† All ACL Flashcard Decks

ACL in Active Directory & LDAP Flashcards

6 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 ACL in Active Directory & LDAP flashcards as text
  1. Which built-in Windows tool automates the process of assigning ACL-based delegated permissions on Active Directory OUs?

    Answer: Delegation of Control Wizard in ADUC

    The Delegation of Control Wizard in ADUC simplifies assigning specific administrative permissions to users or groups on an OU, guiding admins through common delegation scenarios.

  2. What does the 'GenericAll' ACE represent in Active Directory?

    Answer: Full control permission granting all rights over an AD object

    GenericAll is the most powerful ACE in Active Directory, granting complete control over an object including modifying attributes, resetting passwords, and changing the object's ACL.

  3. What is a common Active Directory attack technique that exploits misconfigured ACLs?

    Answer: ACL abuse using overpermissioned ACEs like WriteDACL or GenericAll to escalate privileges

    ACL abuse exploits overly permissive ACEs (such as WriteDACL, GenericWrite, or GenericAll) to escalate privileges or take control of accounts in Active Directory.

  4. What does the 'WriteDACL' permission allow an attacker to do in Active Directory?

    Answer: Modify the DACL of an object to grant themselves additional permissions

    WriteDACL allows a principal to modify an object's DACL, enabling an attacker to grant themselves additional rights such as Full Control over that object.

  5. In OpenLDAP ACL syntax, what does the 'by' clause specify?

    Answer: Who the access rule applies to, such as specific users, authenticated users, or anonymous connections

    The 'by' clause in an OpenLDAP ACL defines who the permission applies to, supporting specifiers like `users`, `anonymous`, `self`, or specific DNs.

  6. What is the purpose of the 'Protected Users' security group in Active Directory?

    Answer: Applies authentication restrictions to reduce credential theft exposure for sensitive accounts

    Accounts in the Protected Users group cannot use NTLM, DES, or RC4 Kerberos encryption, and credentials are not cached, significantly reducing the attack surface for credential-based attacks.