▸case-02 To mitigate LDAP relay attacks (CVE-2017-8563), an engineer needs to configure LDAP channel binding tokens on Active Directory domain controllers. Provide the registry value name and the integer setting that enforces channel binding for all clients without allowing non-supporting clients. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 A system administrator wants to disable plain text unencrypted LDAP authentication on Windows Server Active Directory Domain Controllers and force all clients to use signed LDAP. A common mistake is setting LDAPServerIntegrity to 1, thinking it forces signing. Specify the exact registry key path and DWORD value required on Domain Controllers to strictly require signing. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 In OpenLDAP runtime configuration (cn=config), anonymous binds are permitted by default in older installations. Provide the specific olcSecurity directive option required in cn=config to prohibit anonymous authentication across all connections. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 An administrator needs to audit write and modification operations performed against an OpenLDAP directory database. Name the specific built-in OpenLDAP overlay module used to log directory modification operations. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 Active Directory logs a daily aggregate summary detailing how many unsigned and cleartext LDAP binds occurred. State the Directory Services Event ID that provides this daily summary count in the event log. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 In Windows Active Directory, anonymous LDAP operations can expose user directory objects. An administrator wants to modify the dsHeuristics attribute string on the Directory Service object. Provide the exact 7th character value required in the dsHeuristics string to disable anonymous LDAP operations. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 When hardening an OpenLDAP slapd server, administrators want to reject cleartext directory operations unless StartTLS or LDAPS is active. Specify the olcSecurity flag option that enforces TLS protection for directory operations. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 When documenting directory service security controls for compliance assessment, LDAP access control rules restricting object access based on user identity align to which specific NIST SP 800-53 Access Control family control identifier? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 An engineer needs to harden Active Directory service accounts against Kerberoasting offline password cracking attacks targeting Service Principal Names (SPNs). What service account configuration strategy mitigates Kerberoasting? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 An incident responder is configuring Windows Event Log auditing to identify specific client IP addresses making unsigned LDAP binds against Domain Controllers. Identify the specific Active Directory Directory Services Event ID that records individual client IP addresses and account names attempting unsigned binds. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 When configuring LDAP directory server audit logging for authentication attempts and access events, which NIST SP 800-53 Audit and Accountability control identifier corresponds to audit event logging requirements? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 In OpenLDAP, cleartext password binds are insecure. Which slapd configuration parameter in olcSaslSecProps or olcSecurity enforces a minimum Security Strength Factor (SSF) for authenticated sessions? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 A backend service constructs search filters for an LDAP directory service. User inputs may contain special characters like asterisks. State the two-digit hexadecimal RFC 4515 escape sequence required for the asterisk character in search filters. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 When sanitizing inputs for LDAP directory search filters compliant with RFC 4515, what is the two-digit hexadecimal escape representation for the NULL byte character (0x00)? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 In OpenLDAP olcAccess rules, administrators need to secure the userPassword attribute. Specify the olcAccess access level controls required to allow users to update their own password while preventing other authenticated users from reading password hashes. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 To prevent Denial of Service (DoS) attacks via memory exhaustion from unpaged LDAP queries, Active Directory administrators adjust policy limits in NTDS.dit. What specific LDAP policy attribute controls the maximum number of objects returned in a single search response? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 An administrator wants to decrease the maximum idle connection time for LDAP sessions on Active Directory to prevent connection starvation. Which LDAP policy parameter in LDAPAdminLimits controls idle client session termination? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 According to RFC 4515 LDAP search filter encoding guidelines, how must the backslash character (\) be escaped in a search filter string? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 A network engineer is configuring firewall rules for directory service security. Specify the standard TCP port for implicit LDAPS compared to explicit LDAP with StartTLS. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 LDAPv2 is deprecated and lacks support for SASL and TLS negotiation. How is LDAPv2 authentication disabled in OpenLDAP configuration? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 A security analyst is remediating Active Directory Certificate Services (ADCS) vulnerabilities related to ESC1 where certificate templates allow ENROLLEE_SUPPLIES_SUBJECT. Describe the specific certificate template configuration change to prevent requester-supplied Subject Alternative Names. | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 An administrator wants to secure network shares hosted on a Windows File Server by enforcing SMB Encryption across all client connections via Group Policy. State the GPO registry policy setting used to enforce SMB Encryption on the server. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |