Which term describes a vulnerability that enables impersonation of domain controllers by exploiting Netlogon weakness?

Prepare for the WatchGuard Endpoint Security Essentials Test. Study with multiple choice questions, hints, and explanations. Boost your exam readiness now!

Multiple Choice

Which term describes a vulnerability that enables impersonation of domain controllers by exploiting Netlogon weakness?

Explanation:
Zerologon is the term that describes the Netlogon weakness that allowed impersonation of domain controllers. The flaw in the Netlogon authentication process let an attacker establish a secure channel to a domain controller using a zero-value (all zeros) session key, which could be accepted as a valid logon. With this, an attacker could impersonate any computer in the domain, including a domain controller, effectively taking control of the domain. Patching the vulnerability stops this forgery by ensuring Netlogon authentication cannot be coerced with zero-keys and by resetting impacted credentials after patching. The other options refer to different exploits or techniques (BlueKeep to RDP, EternalBlue to SMB, and DCShadow as a rogue-DC deployment method), none of which describe this Netlogon impersonation weakness.

Zerologon is the term that describes the Netlogon weakness that allowed impersonation of domain controllers. The flaw in the Netlogon authentication process let an attacker establish a secure channel to a domain controller using a zero-value (all zeros) session key, which could be accepted as a valid logon. With this, an attacker could impersonate any computer in the domain, including a domain controller, effectively taking control of the domain. Patching the vulnerability stops this forgery by ensuring Netlogon authentication cannot be coerced with zero-keys and by resetting impacted credentials after patching. The other options refer to different exploits or techniques (BlueKeep to RDP, EternalBlue to SMB, and DCShadow as a rogue-DC deployment method), none of which describe this Netlogon impersonation weakness.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy