Privileged Threat Analytics Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Privileged Threat Analytics flashcards as text
Which data source does CyberArk PTA use to detect suspicious Kerberos activity such as Golden Ticket attacks?
Answer: Windows Event Logs from domain controllers
PTA ingests Windows Event Logs from domain controllers to detect Kerberos anomalies like Golden Ticket and Pass-the-Ticket attacks.
In CyberArk PTA, what does a 'suspected credential theft' alert typically indicate?
Answer: Credentials were extracted from memory using tools like Mimikatz
Suspected credential theft alerts in PTA indicate that credential extraction tools may have dumped passwords or hashes from memory.
How does PTA classify accounts that are discovered performing privileged actions but are not managed by the CyberArk Vault?
Answer: Unmanaged privileged accounts
PTA identifies and classifies accounts performing privileged activity without Vault management as unmanaged privileged accounts.
When PTA detects a threat and automatically responds by rotating a compromised account's password, this capability is known as:
Answer: Automatic response
PTA's automatic response feature triggers actions such as password rotation or account suspension when a threat is confirmed.
Which PTA detection scenario identifies an attacker who has obtained a long-lived Kerberos ticket that does not expire normally?
Answer: Golden Ticket
A Golden Ticket attack forges a Kerberos TGT signed with the KRBTGT hash, producing a ticket with an abnormally long lifetime.
What is the role of the PTA sensor deployed in the network?
Answer: It captures and forwards network traffic metadata to the PTA server for analysis
The PTA sensor mirrors network traffic and forwards relevant metadata to the PTA server for behavioral and threat analysis.
Which CyberArk component does PTA integrate with to automatically suspend a compromised privileged account?
Answer: PAM (Privileged Access Manager) / Vault
PTA integrates with CyberArk PAM/Vault to execute automatic responses such as disabling or rotating accounts flagged as compromised.