During an incident response investigation into an internal identity compromise involving Kerberos ticket forgery (Pass-the-Ticket) across domain-joined assets, an analyst must act quickly. Which of the following actions represent appropriate containment measures to execute prior to moving into the eradication phase? (Select TWO.)
- Isolate impacted host workstations from the network via endpoint controls while maintaining system power.Cevap
- Reset compromised domain account passwords and purge active Kerberos ticket sessions across targeted services.Cevap
- CRe-image all primary Active Directory Domain Controllers immediately to ensure malware binaries are removed.
- DModify perimeter firewall ACLs to block all incoming HTTP and HTTPS web traffic.
Cevap
Isolating impacted workstations from the network while maintaining system power, and resetting compromised domain account passwords while purging active Kerberos ticket sessions.
Effective containment during a Kerberos ticket attack requires halting lateral movement and revoking unauthorized access while maintaining forensic evidence integrity. Isolating compromised host endpoints prevents traffic propagation without clearing volatile RAM needed for memory forensics. Additionally, resetting compromised account passwords and invalidating forged session tickets revokes the attacker's ability to authenticate to other domain services.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Containment Strategies for Identity Compromise