Soru

Zorluk: ZorIncident Response Process and Playbooks

During an incident response investigation into an internal identity compromise involving Kerberos ticket forgery (Pass-the-Ticket) across domain-joined assets, an analyst must act quickly. Which of the following actions represent appropriate containment measures to execute prior to moving into the eradication phase? (Select TWO.)

  1. Isolate impacted host workstations from the network via endpoint controls while maintaining system power.Cevap
  2. Reset compromised domain account passwords and purge active Kerberos ticket sessions across targeted services.Cevap
  3. C
    Re-image all primary Active Directory Domain Controllers immediately to ensure malware binaries are removed.
  4. D
    Modify perimeter firewall ACLs to block all incoming HTTP and HTTPS web traffic.

Cevap

Isolating impacted workstations from the network while maintaining system power, and resetting compromised domain account passwords while purging active Kerberos ticket sessions.
Effective containment during a Kerberos ticket attack requires halting lateral movement and revoking unauthorized access while maintaining forensic evidence integrity. Isolating compromised host endpoints prevents traffic propagation without clearing volatile RAM needed for memory forensics. Additionally, resetting compromised account passwords and invalidating forged session tickets revokes the attacker's ability to authenticate to other domain services.

Adım Adım Çözüm

1
Identify the primary objective during the containment phase of an identity-based attack.
The goal is to stop lateral propagation and unauthorized access without destroying volatile evidence.
Containment limits incident impact before proceeding to permanent removal of threat artifacts.
2
Evaluate host-level containment controls.
Network isolation of affected endpoints stops lateral spread, while leaving machines powered preserves volatile RAM containing Kerberos ticket caches.
Powering down hosts clears RAM, hindering digital forensics.
3
Evaluate identity and authentication containment controls.
Resetting password hashes and revoking active Kerberos tickets terminates active attacker sessions.
Identity controls stop stolen credentials from granting further access to network resources.

Anahtar Kavram

Incident Response Containment Strategies for Identity Compromise
Bu soruyu puanla