Q: 2
[Information Gathering and Vulnerability Scanning]
A penetration tester is configuring a vulnerability management solution to perform credentialed
scans of an Active Directory server. Which of the following account types should the tester provide to
the scanner?
Options
Discussion
I think A works for most scans, since read-only should let the scanner pull config info without major risks. B seems like overkill and a big privilege escalation threat if creds leak. Anyone else see similar questions suggest A as a safer trap pick?
Why not just use A here? Isn't B a privilege escalation risk for the scan?
Probably B, since only a domain admin will have the needed permissions for a proper credentialed scan on an AD server.
Be respectful. No spam.