nerdexam
CompTIA

PT0-003 · Question #72

A penetration tester is configuring a vulnerability management solution to perform credentialed scans of an Active Directory server. Which of the following account types should the tester provide to…

The correct answer is B. Domain administrator. To perform credentialed scans on an Active Directory (AD) server, the scanner requires high-level access to retrieve system configuration, patch levels, and user rights. A Domain Administrator account ensures full visibility into domain resources and permissions, which is…

Submitted by olafpl· Mar 6, 2026Vulnerability Discovery and Analysis

Question

A penetration tester is configuring a vulnerability management solution to perform credentialed scans of an Active Directory server. Which of the following account types should the tester provide to the scanner?

Options

  • ARead-only
  • BDomain administrator
  • CLocal user
  • DRoot

How the community answered

(31 responses)
  • A
    10% (3)
  • B
    81% (25)
  • C
    6% (2)
  • D
    3% (1)

Explanation

To perform credentialed scans on an Active Directory (AD) server, the scanner requires high-level access to retrieve system configuration, patch levels, and user rights. A Domain Administrator account ensures full visibility into domain resources and permissions, which is essential for a complete vulnerability assessment.

Topics

#credentialed scanning#Active Directory security#vulnerability scanning#privilege management

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice