Which term refers to registers rogue domain controllers to push changes into Active Directory?

Prepare for the WatchGuard Endpoint Security Essentials Test. Study with multiple choice questions, hints, and explanations. Boost your exam readiness now!

Multiple Choice

Which term refers to registers rogue domain controllers to push changes into Active Directory?

Explanation:
Registering rogue domain controllers to push changes into Active Directory relies on how AD replication works. DCShadow is the technique that does this: it creates an unauthorized domain controller inside the domain and uses the normal replication process to propagate changes from that rogue DC to all other DCs. Because replication is a trusted, standard mechanism in AD, changes pushed through this fake DC can appear legitimate, enabling manipulation such as adding or modifying accounts and privileges across the environment. DCSync, on the other hand, involves querying a legitimate domain controller to pull sensitive data like password hashes via replication, not pushing changes or introducing a new DC. EternalBlue is an SMB vulnerability exploit used for lateral movement, not AD replication. Code Injection is a general technique for injecting code, not specific to pushing changes through AD replication.

Registering rogue domain controllers to push changes into Active Directory relies on how AD replication works. DCShadow is the technique that does this: it creates an unauthorized domain controller inside the domain and uses the normal replication process to propagate changes from that rogue DC to all other DCs. Because replication is a trusted, standard mechanism in AD, changes pushed through this fake DC can appear legitimate, enabling manipulation such as adding or modifying accounts and privileges across the environment.

DCSync, on the other hand, involves querying a legitimate domain controller to pull sensitive data like password hashes via replication, not pushing changes or introducing a new DC. EternalBlue is an SMB vulnerability exploit used for lateral movement, not AD replication. Code Injection is a general technique for injecting code, not specific to pushing changes through AD replication.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy