Active Directory and Kerberos Flashcards

1
Q

Windows Domain

A

Group of users and computers under the administration of a given business

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Active Directory

A

Single repository to centralize the administration of common components of a network
Provides centralized identity management
Allows you to configure and apply security policies to users and computers as needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Domain Controller (DC)

A

Server that runs AD services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AD DS

A

Active Directory Domain Service
Acts as a catalog that holds the info of all the “objects” that exist on your network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security Principal

A

Objects (mostly users) that can be authenticated by the domain and assigned privileges over resources or act upon those resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

OU

A

Organizational Unit
Container objects that allow you to classify users and machines
Mainly used to define sets of users with similar policing requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

GPO

A

Group Policy Object
Collection of settings that can be applied to OUs
Can contain policies aimed at either users or computers, allowing you to set a baseline on specific machines and identities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

GPOs are distributed to the network via a network share called ____

A

SYSVOL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Tree

A

Partitioned structure with a root domain and branching subdomains that can be managed independently
Gives us better control over who can access what in the domain
Policies can be configured independently for each domain in the tree

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Forest

A

The union of several trees with different namespaces into the same network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Domains arranged in trees and forests are joined together by ___

A

Trust relationships
These allow you to authorize a user from Domain A to access resources from Domain B
Can have one way or two way trust relationships

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Kerberos

A

The default authentication service for Microsoft Windows domains. It is intended to be more “secure” than NTLM by using third party ticket authorization as well as stronger encryption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Ticket Granting Ticket (TGT)

A

Authentication ticket used to request service tickets from the Ticket Granting Service for specific resources from the domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Key Distribution Center (KDC)

A

Service for issuing TGTs and service tickets that consist of the Authentication Service and the Ticket Granting Service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Kerberoasting- what is it, how to mitigate

A

Allows a user to request a service ticket for any service with a registered SPN then use that ticket to crack the service password.
Enforce strong passwords for service accounts, and don’t allow them domain admin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

AS-REP Roasting- what is it, how to mitigate

A

AS-REP Roasting dumps the krbasrep5 hashes of user accounts that have Kerberos pre-authentication disabled.
Enforce strong passwords for user accounts, and enforce Pre-Authentication

17
Q

What is the best mitigation to protect a Domain Admin account from a Pass the Ticket attack?

A

Don’t allow Domain Admin accounts onto any system except Domain Controller. Then their ticket can’t be found.

18
Q

KRBTGT

A

A KRBTGT is the service account for the KDC this is the Key Distribution Center that issues all of the tickets to the clients.
If you impersonate this account and create a golden ticket from the KRBTGT you give yourself the ability to create a service ticket for anything you want.

19
Q

mimikatz

A

Both an exploit on Microsoft Windows that extracts passwords stored in memory and software that performs that exploit. Used in pass the hash attacks