Skip to content
Tech Interview Prep home
Technical interview guide

Directory Services (LDAP, Active Directory)

The centralized store of identities, groups, and attributes that most enterprise authentication and authorization builds on.

Read
45 min
Practice MCQs
25
Interview QA
25
Edition
v5
Editorial status
Reviewed

Scope: LDAP RFC 4511/4513/4514/4515, Kerberos V5 RFC 4120, and current Microsoft AD DS, CISA, and NIST guidance reviewed 2026-09-04.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Explain how an application should integrate with a directory.

QA-2

Design directory identity correlation and rename handling.

QA-3

Prevent LDAP injection in login and search flows.

QA-4

Secure LDAP client transport and bind behavior.

QA-5

Design LDAP TLS failure and certificate rotation behavior.

QA-6

Design OU, group, and application-role boundaries.

QA-7

Resolve and govern nested group access.

QA-8

Explain a Kerberos application authentication flow.

QA-9

Operate Kerberos time and replay controls.

QA-10

Design delegated Kerberos access for a multi-tier service.

QA-11

Manage service principal names safely.

QA-12

Design applications for directory replication behavior.

QA-13

Implement urgent directory account containment.

QA-14

Design a least-privilege LDAP service account.

QA-15

Secure LDAP referral and cross-directory behavior.

QA-16

Design performant and safe LDAP searches.

QA-17

Choose directory endpoints for forest-wide lookup.

QA-18

Design delegated directory administration.

QA-19

Migrate legacy directory service accounts.

QA-20

Roll out LDAP signing and channel-binding requirements.

QA-21

Design directory security monitoring and response.

QA-22

Design and exercise directory forest recovery.

QA-23

Handle restored or long-offline directory replicas safely.

QA-24

How does the Active Directory Recycle Bin differ from tombstone reanimation, and what are the operational requirements and irreversible impacts of enabling it?

QA-25

How do one-way and two-way external versus forest trusts differ in Active Directory, and how does SID filtering prevent elevation of privilege across those trust boundaries?