Loading assessment title...
Assessment
1. Which statement best describes PetitPotam in a defensive Windows identity model?
A name associated with EFSRPC coercion research that can be chained with NTLM relay and insecure relay targets.
A universal name for every NTLM relay technique in Windows networks.
A password-cracking technique that directly extracts plaintext domain credentials.
A certificate-template misconfiguration that exists only on standalone certificate authorities.
2. A Windows host is induced to authenticate to an unintended destination. Which concept is this before any relay target accepts the exchange?
Certificate-based impersonation.
Forced authentication.
Strong certificate mapping.
Directory replication abuse.
3. Why can NTLM relay succeed without the attacker knowing the password?
NTLM stores the password in the IIS log for compatibility.
NTLMv2 converts the password to a certificate automatically.
The authentication exchange can be forwarded to a target that accepts it for the relayed identity.
Kerberos tickets are always embedded inside NTLM messages.
4. What is the legitimate purpose of EFSRPC according to Microsoft protocol documentation?
Issuing authentication certificates for domain controllers.
Disabling NTLM on sensitive servers.
Auditing certificate templates for ESC8.
Managing encrypted data stored remotely and accessed over a network.
5. In the AD CS relay path, what does an insecure enrollment endpoint contribute to the chain?
It may accept relayed NTLM authentication and issue a certificate under the relayed identity.
It cracks the NTLM challenge-response and stores the plaintext password.
It disables EFSRPC on every domain controller.
It prevents certificate-based authentication by enforcing strong mapping.
6. Which mitigation most directly addresses ESC8 on AD CS web enrollment endpoints?
Only enabling a certificate revocation list publication schedule.
Requiring HTTPS and correctly enabling Extended Protection for Authentication on required IIS enrollment endpoints.
Increasing the certificate validity period for domain controller certificates.
Allowing NTLM but disabling Kerberos for enrollment traffic.
7. Why is HTTPS alone not always a complete NTLM relay defense for IIS-backed enrollment?
HTTPS does not encrypt HTTP headers.
HTTPS disables all certificate issuance.
Transport protection alone may not bind the inner Windows authentication to the intended channel or service.
HTTPS converts NTLM into anonymous authentication.
8. What is the most appropriate first step before broadly restricting NTLM in a legacy enterprise?
Remove every certificate template immediately.
Disable every domain controller network interface except one.
Assume all NTLM is malicious and block it without exception.
Audit NTLM usage, identify dependencies, classify necessity, and remediate avoidable fallback.
9. Which Microsoft Defender XDR alert name is currently relevant to PetitPotam-style EFSRPC coercion detection?
Suspicious network connection over Encrypting File System Remote Protocol.
Guaranteed domain compromise through AD CS.
Certificate authority web enrollment disabled successfully.
Kerberos ticket renewal using safe template mapping.
10. A posture dashboard reports insecure AD CS certificate enrollment IIS endpoints. What does that finding most directly indicate?
An endpoint exposure exists that should be reviewed and remediated, commonly labeled ESC8.
A certificate was definitely issued to an attacker.
A certificate was definitely used for Kerberos authentication.
EFSRPC is disabled on every domain controller.
11. How should defenders treat strong certificate mapping in relation to EPA on enrollment endpoints?
Strong mapping replaces EPA because it prevents all relayed enrollment.
Strong mapping is useful for certificate-based authentication, but it does not replace securing enrollment endpoints against relay.
Strong mapping is only relevant to SMB signing.
Strong mapping disables every authentication-capable certificate template.
12. Which evidence combination most strongly raises concern for a PetitPotam-to-AD-CS chain?
A normal password change followed by a scheduled certificate revocation list publication.
An IIS service restart followed by no certificate requests.
Unusual EFSRPC activity, outbound authentication from a sensitive host, NTLM to AD CS enrollment, and suspicious certificate issuance.
A domain controller applying Group Policy from SYSVOL.
13. During incident response, why is certificate revocation not the only action after suspicious certificate issuance?
Revocation has no meaning in Windows PKI.
Revocation may have propagation and cache limits, and responders still need to determine certificate use and fix the exposed chain.
Revocation automatically resets every machine account password.
Revocation disables all AD CS web enrollment endpoints.
14. Which validation approach best avoids creating an operational exploitation guide or production risk?
Trigger coerced authentication from production domain controllers repeatedly until an alert appears.
Issue a domain controller certificate through a relayed production flow to prove impact.
Use configuration inspection, telemetry review, controlled lab testing, and authorized non-destructive production checks.
Disable all monitoring so the test cannot generate false positives.
15. Which roadmap best summarizes resilient defense?
Patch one EFSRPC function and consider all NTLM relay risk closed.
Keep NTLM enabled but rely on certificate revocation after suspicious activity.
Use HTTPS on AD CS while leaving EPA, templates, and NTLM unchanged.
Secure coercion surfaces, authentication protocols, relay destinations, certificate issuance, monitoring, and validation together.
Submit Quiz
Previous