Skip to main content
AD Academy

Interview questions: junior / mid

The same material, repackaged the way it gets asked in a helpdesk, NOC or SOC interview.

Active DirectoryWhat is Active Directory and why does a company need it?

Short answerMicrosoft's directory service: users, computers, groups and policies live in one place. Instead of a local account per machine, one account covers the whole organisation with central permissions.

What they are really checking: Whether you grasp central management, not just "a server with passwords".

Domain ControllerHow does a Domain Controller differ from a Global Catalog?

Short answerA DC holds the domain database and authenticates users. A GC is a DC that also keeps a partial replica of every object in the forest and serves cross-domain search and logon (port 3268).

What they are really checking: Understanding forest vs domain.

DNSWhy does AD break without DNS?

Short answerClients locate a DC through SRV records (_ldap._tcp.dc._msdcs). If the NIC points at the router or 8.8.8.8 instead of the DC, there is no logon, no GPO and no domain join.

What they are really checking: The single most common helpdesk ticket.

DHCPDescribe how a client gets an IP address from DHCP.

Short answerDORA: Discover, Offer, Request, Acknowledge. A 169.254.x.x address means no DHCP answer arrived at all.

What they are really checking: Diagnosing "no internet" without guessing.

GPOWhat is Group Policy and in what order does it apply?

Short answerA way to push settings to users and computers. Order is LSDOU: Local, Site, Domain, OU — the last one wins. gpupdate /force applies now, gpresult /r shows what actually landed.

What they are really checking: Whether you verify results, not just create policies.

GroupsSecurity Group vs Distribution Group?

Short answerA security group can be placed in an ACL and grant permissions; a distribution group only serves email lists.

What they are really checking: Access-management basics.

TroubleshootingA user keeps getting locked out. What do you do?

Short answerCheck event 4740 on the DC for the source, then hunt for a stale session, mapped drive, service running with an old password, or a phone with cached mail. Unlock only after finding the cause.

What they are really checking: Structured thinking instead of repeated unlocks.

NetworkWhich ports matter in an AD environment?

Short answer53 DNS, 88 Kerberos, 389 LDAP, 636 LDAPS, 445 SMB, 3268 Global Catalog, 3389 RDP, 123 NTP.

What they are really checking: Ability to suspect a firewall block.

HelpdeskA user says their password will not change. Why?

Short answerMinimum password age not reached, complexity or history policy rejecting it, clock skew, or the machine cannot reach a DC at all. Check the password policy and the event log.

What they are really checking: Connecting policy to real behaviour.