List of questions
Related questions
Question 536 - 312-50v12 discussion
A malicious user has acquired a Ticket Granting Service from the domain controller using a valid user's Ticket Granting Ticket in a Kerberoasting attack. He exhorted the TGS tickets from memory for offline cracking. But the attacker was stopped before he could complete his attack. The system administrator needs to investigate and remediate the potential breach. What should be the immediate step the system administrator takes?
A.
Perform a system reboot to clear the memory
B.
Delete the compromised user's account
C.
Change the NTLM password hash used to encrypt the ST
D.
invalidate the TGS the attacker acquired
Your answer:
0 comments
Sorted by
Leave a comment first