▸case-23 Following the execution of a scheduled privileged account discovery scan, a team lead suggests keeping only ephemeral terminal output. What report artifact must be generated to fulfill auditing and compliance requirements? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 In Microsoft Entra ID privilege inventory, an engineer searches for accounts with the Directory Readers role. What specific Entra ID role name confers highest administrative privileges across the tenant? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 A security engineer plans to execute untested privilege discovery scripts directly against production Active Directory Domain Controllers during high-volume business hours. Where should discovery procedures be tested prior to production execution? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 Audit logs from privilege discovery scanning scripts are currently retained only in local flat files on the scanner workstation. Where must these audit logs be forwarded to ensure centralized compliance logging? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 When discovering privileged users on Linux hosts, an analyst checks only /etc/passwd for UID 0. What system configuration file or directory must be audited to find non-root accounts granted root escalation rights via sudo? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 When auditing Google Cloud Platform IAM bindings for top-level administrative accounts, an auditor searches for roles/viewer. What GCP IAM role at the organization level grants full administrative control? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 In a PostgreSQL privilege discovery script, a developer queries pg_roles checking rolcanlogin. Which boolean column in pg_roles indicates that the account possesses full database superuser privileges? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 When auditing AWS IAM policies to identify roles with full administrator rights, a reviewer checks for ReadOnlyAccess. What IAM policy statement effect and action combination signifies unrestricted administrative power across all resources? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 In Active Directory privilege auditing, an engineer queries only the Domain Admins group. Name another primary Active Directory privileged group that grants forest-wide administrative access. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 When discovering local administrator accounts across Windows workstations, an auditor recommends storing static passwords in a spreadsheet. What Active Directory integrated feature automatically manages and rotates local administrator account passwords on domain-joined machines? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 A system administrator requests a Python script to set up HashiCorp Vault automatic 30-day password rotation policies and secret engine backend bindings for privileged database accounts. Does account discovery software handle configuring secret rotation schedules within PAM vaults? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 An application owner asks for instructions on configuring SAML 2.0 single sign-on (SSO) identity provider metadata for end-user web application logins. Does the domain of privileged account discovery cover end-user application SSO integration? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 After an automated discovery scan locates unmanaged local administrative accounts, into what class of security management platform must these accounts be onboarded? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-24 An analyst prepares to run network-wide privileged port and service scans across a client's network without prior written approval. What prerequisite must be established before conducting any security discovery activities? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 When inventorying Microsoft SQL Server database instances for privileged access, an analyst proposes querying sp_helprole for db_datareader. What fixed server role grants full administrative privilege over the SQL Server instance? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 To locate service accounts in Active Directory that are potential targets for privilege escalation, a developer plans to filter by userAccountControl=512. Which LDAP attribute must be checked to locate accounts configured with Service Principal Names? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 An operational team asks for automated playbooks to immediately disable and revoke privileges for accounts identified as domain admins during a live inventory scan. How should an automated privilege discovery workflow handle these accounts without performing unauthorized active account modification or deactivation? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 During a security architecture review, identify the NIST 800-53 control identifier governing least privilege for service accounts, addressing a proposal that listed AC-7. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 When writing LDAP queries for Active Directory to discover accounts protected by SDProp with administrative privileges, an engineer suggests querying objectClass=user without filter flags. What LDAP attribute filter identifies accounts marked with administrative protection? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 To align user and service identification verification in discovery scans with NIST 800-53, determine the control identifier for User and Service Identification, replacing a draft that cited IA-5. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 In a security audit for an enterprise privilege inventory system, map the account lifecycle management requirement to its NIST 800-53 security control identifier, correcting a draft that proposed AC-17. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 When mapping authorization enforcement policies for discovery scripts against NIST 800-53 controls, a junior engineer suggested AU-12. Which NIST 800-53 control identifier represents Access Enforcement? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 An auditor asks for the NIST 800-53 control identifier that covers audit logging of privilege discovery events and authentication attempts, replacing an incorrect submission of AU-6. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 A developer prepares an environment deployment manifest for privilege discovery tools and specifies Python 2.7. What minimum Python version requirement must be specified in the deployment prerequisites? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |