← Back to Active Directory Foundations

Access Control Lists Quiz

6 questions


1.What is the DACL on an Active Directory object?

2.Why is WriteDACL on an AD object effectively as dangerous as GenericAll?

3.How does ACL inheritance create unintended privilege escalation paths?

4.A compromised account has WriteDACL on the Domain Admins group. Why is this a critical finding even though the account is not a member of Domain Admins?

5.What distinguishes ACL-based attack paths from group-membership-based paths?

6.An interviewer asks: 'Why do ACL misconfigurations exist in well-managed AD environments?' Which answer best explains the root cause?