← Back to Security Identifiers and Security Principals

Security Identifiers and Security Principals Quiz

7 questions


1.What is a security principal in Windows?

2.What makes a SID different from a username as an identifier?

3.An administrator renames the built-in Administrator account, hoping to make it harder for an attacker to find. What actually happens to that account's identity?

4.A team deletes a compromised account and creates a brand new account using the exact same username, expecting a clean slate with matching permissions. What actually happens?

5.What distinguishes a well-known SID, like S-1-1-0 for Everyone, from a well-known RID, like 500 for the built-in Administrator?

6.During enumeration, why would an experienced tester resolve accounts by SID instead of trusting the display name shown in a directory listing?

7.What does the sIDHistory attribute allow, and why is it treated as sensitive?