New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 4 Topic 1 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 4 Topic 1 Discussion

312-50v13 Exam Topic 1 Question 4 Discussion:
Question #: 4
Topic #: 1

A malicious user has acquired a Ticket Granting Service from the domain controller using a valid user's Ticket Granting Ticket in a Kerberoasting attack. He exhorted the TGS tickets from memory for offline cracking. But the attacker was stopped before he could complete his attack. The system administrator needs to investigate and remediate the potential breach. What should be the immediate step the system administrator takes?


A.

Perform a system reboot to clear the memory


B.

Delete the compromised user's account


C.

Change the NTLM password hash used to encrypt the ST


D.

invalidate the TGS the attacker acquired


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.