▸case-19 To decrease event log disk space utilization on Active Directory Domain Controllers, an administrator disables Security Audit policy for Audit Logon and Audit Account Management events. Evaluate this change against NIST 800-53 AU-3 requirements for Active Directory tiering. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 A system architect categorizes Active Directory Federation Services (AD FS) servers and Enterprise PKI Certification Authorities as Tier 1 assets because they run web application software on Internet Information Services (IIS). Assess this resource tier classification. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 A Domain Admin logs into a standard end-user workstation (Tier 2) using interactive logon to resolve a local registry configuration issue. Explain why this action poses a severe security risk and state what account credential should have been used instead. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 An Active Directory administrator needs to configure custom sync rules in Microsoft Entra Connect (formerly Azure AD Connect) to prevent specific staging accounts from synchronizing to Microsoft Entra ID. How are custom attribute synchronization rules created and edited within Entra Connect? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 A sysadmin proposes applying a single static local administrator password across all Tier 1 servers and Tier 2 workstations via Group Policy Preferences to streamline emergency maintenance. Identify the primary security risk created by this approach in a tiered Active Directory environment, and name the standard tool that should be deployed instead. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 A Tier 1 server administrator requests delegated Write permissions on the Organizational Unit (OU) that contains Domain Controllers and Tier 0 administrative accounts so they can update user account contact details. Explain whether this delegation should be granted. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 A support team requests permission for Tier 2 helpdesk staff to remotely connect via RDP to Tier 0 Privileged Access Workstations (PAWs) to perform background software updates and routine maintenance. Evaluate this request under the PAW threat model. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 An enterprise architect is deploying an Enhanced Security Admin Environment (ESAE) administrative forest (Red Forest) to manage an existing production Active Directory forest. They propose establishing a two-way transitive forest trust so administrative forest users can manage production resources and production forest users can access administrative utilities. Evaluate this proposed trust architecture and specify the required trust configuration. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 An administrator wants to protect high-privilege Active Directory accounts from credential caching, NTLM fallback, and DES encryption by adding them to a built-in AD group. Identify this built-in Active Directory security group and state which administrative tier of accounts should primarily be added to it. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 A software installation guide for a Tier 1 enterprise resource planning (ERP) database recommends running its service account under the Domain Admins group to prevent permission issues during setup. Detail how this service account should be configured to conform to administrative tiering rules. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 An Active Directory security team wants to enforce strict Kerberos authentication boundaries for Domain Admins so that these accounts cannot be used to authenticate against Tier 1 application servers or Tier 2 workstations, even if a user attempts to do so. Which specific Active Directory feature introduced in Windows Server 2012 R2 restricts account authentication to designated host groups? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 During a security assessment of a Active Directory deployment running Windows LAPS, an auditor notes that the Organizational Unit permissions grant read access on local administrator password attributes to Authenticated Users. Analyze the security impact of this permission setting. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 An IT department proposes replacing dedicated physical Privileged Access Workstations with a remote desktop jump box running as a virtual machine on a Tier 1 Hyper-V cluster managed by Tier 1 server administrators. Evaluate whether this virtualized jump box meets Tier 0 isolation requirements. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 A network security team sets up a centralized Windows Server jump box where Tier 1 application administrators and Tier 0 Domain Admins log in concurrently to manage their respective targets. Explain how administrative jump hosts must be structured in a compliant tiered Active Directory deployment. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 A backup administrator schedules automated System State backups for all Tier 0 Domain Controllers and configures the target backup location as a network share hosted on a Tier 2 storage array managed by desktop support personnel. Analyze the security risk of this configuration. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-23 An administrator wants to create a Fine-Grained Password Policy (FGPP) using a Password Settings Object (PSO) in Active Directory to require 16-character passwords for a specific executive group. What administrative tools or PowerShell cmdlets are used to construct and apply a PSO? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 When configuring Group Policy Objects (GPOs) to enforce administrative tier separation, which specific User Rights Assignment policies must be applied on Tier 0 Domain Controllers to explicitly prevent lower-tier accounts from logging on? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 A system administrator responsible for Tier 1 line-of-business application servers needs to troubleshoot a DNS resolution issue directly on a Tier 0 Active Directory Domain Controller. They plan to log into the Domain Controller using their Tier 1 administrative credential. Explain whether this logon attempt should be permitted and how access must be configured under Active Directory administrative tiering rules. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 An IT manager regularly uses an Enterprise Admins account to perform routine daily administration on a Tier 1 Microsoft SQL Server cluster. Evaluate this operational practice against least privilege principles and explain how administrative accounts should be assigned. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-24 A security analyst wants to review default Kerberos ticket expiration settings in Windows Group Policy under Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Kerberos Policy. What are the standard default values in Active Directory for user ticket lifetime and service ticket lifetime? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 A Tier 0 Active Directory administrator requests permission to install Microsoft Outlook and a general web browser on their Privileged Access Workstation (PAW) so they can read emails and check vendor documentation while managing Domain Controllers. Explain whether this software configuration is permitted on a hardened PAW and describe how daily user activity should be partitioned. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 An Active Directory team attempts to deploy Authentication Policy Silos in an existing Active Directory domain that currently operates at a Domain Functional Level (DFL) of Windows Server 2008 R2. What minimum Domain Functional Level and Kerberos setting are required for Authentication Policy Silos to function? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 To speed up end-user ticket resolution, an IT department proposes granting Tier 2 helpdesk technicians Remote Desktop (RDP) access to Tier 1 application servers using their existing Tier 2 helpdesk administrative accounts. Assess this proposed privilege assignment against the Active Directory tiered administration model and provide corrective guidance. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 An organization allows Tier 0 Domain Admins to authenticate remotely over VPN using single-factor password authentication, provided the password length is at least 20 characters. Evaluate this control against ESAE guidelines and NIST 800-53 IA-2 requirements for privileged identity access. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |