Loading assessment title...

Assessment

1. Which statement best describes PetitPotam in a defensive Windows identity model?
2. A Windows host is induced to authenticate to an unintended destination. Which concept is this before any relay target accepts the exchange?
3. Why can NTLM relay succeed without the attacker knowing the password?
4. What is the legitimate purpose of EFSRPC according to Microsoft protocol documentation?
5. In the AD CS relay path, what does an insecure enrollment endpoint contribute to the chain?
6. Which mitigation most directly addresses ESC8 on AD CS web enrollment endpoints?
7. Why is HTTPS alone not always a complete NTLM relay defense for IIS-backed enrollment?
8. What is the most appropriate first step before broadly restricting NTLM in a legacy enterprise?
9. Which Microsoft Defender XDR alert name is currently relevant to PetitPotam-style EFSRPC coercion detection?
10. A posture dashboard reports insecure AD CS certificate enrollment IIS endpoints. What does that finding most directly indicate?
11. How should defenders treat strong certificate mapping in relation to EPA on enrollment endpoints?
12. Which evidence combination most strongly raises concern for a PetitPotam-to-AD-CS chain?
13. During incident response, why is certificate revocation not the only action after suspicious certificate issuance?
14. Which validation approach best avoids creating an operational exploitation guide or production risk?
15. Which roadmap best summarizes resilient defense?