20 cards · Foundations, Practitioner, Applied, Advanced, Expert
Identity & AD interview questions and practice topics
Identity and Active Directory: Kerberos and NTLM attacks such as Kerberoasting and pass-the-hash, OAuth and OIDC, SSO, MFA bypass and privilege escalation in AD. Identity is the new perimeter, and interviewers know it.
Each card is a topic to explain out loud against the clock: 12 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick Identity & AD as a focus.
L1 Foundations What it is
L2 Practitioner How it works
- AS-REP RoastingExplain
- How Kerberos Authentication WorksWalk me through what happens on the wire when a domain user opens a file share.Explain · Interview
- OAuth 2.0 Authorization Code + PKCEWhy is authorization code with PKCE the recommended OAuth flow for mobile and single-page apps?Explain · Interview
- Pass-the-HashWhy can an attacker log in with a password hash without ever cracking it?Explain · Interview
- Passkeys and FIDO2Deep dive · Explain
- Password Spray in ProgressIncident
L3 Applied Abuse and defence in real systems
- DCSyncAn attacker ran DCSync. What rights did they need and how do you spot it?Explain · Interview
- Impossible Travel Sign-InWalk me through how you triage an impossible travel alert where MFA passed.Incident · Interview
- KerberoastingWhat is Kerberoasting and how would you both detect and prevent it?Explain · Interview · Deep dive
- Malicious OAuth App ConsentHow do you respond to an illicit consent grant, and why does resetting passwords not fix it?Incident · Interview
- New Domain Admin at 2amIncident
L4 Advanced Edge cases, bypasses, trade-offs
- AD Certificate Services RiskExplain · Deep dive
- AD Tiering ModelExplain · Deep dive
- Golden vs Silver TicketsCompare golden and silver tickets: what key does each need, and which is harder to detect?Explain · Interview · Deep dive
- NTLM RelayExplain NTLM relay and the controls that actually break it.Explain · Interview · Deep dive
L5 Expert Research-grade, architecture-level
Other domains
Web AppSec · Network · Cloud · Cryptography · Blue team / DFIR · Malware & intel · Famous breaches · GRC · AI security