Group 06: Windows and Active Directory

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/33

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:19 PM on 7/28/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

34 Terms

1
New cards
What is Active Directory?
Microsoft’s directory service for centrally managing users, computers, groups, authentication, and security policies.
2
New cards
What is a domain?
A centrally managed collection of users, computers, groups, and policies.
3
New cards
What is a domain controller?
A server that stores Active Directory information and authenticates users and computers.
4
New cards
What is the difference between a local and domain account?
A local account exists on one computer, while a domain account is centrally managed and can access authorized domain resources.
5
New cards
What is Group Policy?
A feature used to centrally configure operating-system and security settings across domain systems.
6
New cards
What is Kerberos?
A ticket-based authentication protocol commonly used in Active Directory environments.
7
New cards
What is NTLM?
An older Windows challenge-response authentication protocol that may be used when Kerberos is unavailable.
8
New cards
What is LDAP?
A protocol used to query and manage directory-service information.
9
New cards
What is LSASS?
A Windows process responsible for security policies, authentication, and credential-related information.
10
New cards
Why do attackers target LSASS?
It may contain password hashes, Kerberos tickets, tokens, or other credentials useful for privilege escalation and lateral movement.
11
New cards
What is PowerShell?
A Windows command-line shell and scripting language used for administration and frequently abused by attackers.
12
New cards
What is a scheduled task?
A Windows feature that executes commands or programs at defined times or conditions and can be abused for persistence.
13
New cards
What is a Windows service?
A background process that can start automatically and may be abused for execution or persistence.
14
New cards
What is privilege escalation?
Gaining permissions beyond those originally assigned.
15
New cards
What is lateral movement?
Moving from one compromised system or account to another inside an environment.
16
New cards
What is pass-the-hash?
Using a stolen password hash to authenticate without knowing the plaintext password.
17
New cards
What is pass-the-ticket?
Reusing a stolen Kerberos ticket to access resources.
18
New cards
What does Event ID 4624 indicate?
A successful Windows logon.
19
New cards
What does Event ID 4625 indicate?
A failed Windows logon.
20
New cards
What does Event ID 4648 indicate?
A logon attempt using explicitly supplied credentials.
21
New cards
What does Event ID 4672 indicate?
Special administrative privileges were assigned to a logon session.
22
New cards
What does Event ID 4688 indicate?
A new process was created when process-creation auditing is enabled.
23
New cards
What does Event ID 4698 indicate?
A scheduled task was created.
24
New cards
What does Event ID 4720 indicate?
A user account was created.
25
New cards
What does Event ID 4722 indicate?
A user account was enabled.
26
New cards
What does Event ID 4728 indicate?
A member was added to a global security group.
27
New cards
What does Event ID 4732 indicate?
A member was added to a local security group.
28
New cards
What does Event ID 4740 indicate?
A user account was locked out.
29
New cards
What does Event ID 4768 indicate?
A Kerberos ticket-granting ticket was requested.
30
New cards
What does Event ID 4769 indicate?
A Kerberos service ticket was requested.
31
New cards
What does Event ID 7045 indicate?
A new Windows service was installed.
32
New cards
What does Microsoft Defender Event ID 1116 indicate?
Microsoft Defender detected malware or potentially unwanted software.
33
New cards
What does Microsoft Defender Event ID 1117 indicate?
Microsoft Defender took action against detected malware or potentially unwanted software.
34
New cards
Why should event IDs never be interpreted alone?
Analysts must review the user, process, system, timestamp, source, surrounding events, and business contex