Privileged Threat Analytics Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Privileged Threat Analytics flashcards as text
Which PTA detection identifies when a user account authenticates from two geographically distant locations within an impossibly short time window?
Answer: Impossible travel alert
Impossible travel alerts fire when the same account authenticates from locations that cannot be reached within the elapsed time, suggesting credential compromise.
In PTA's risk scoring model, which factor would MOST increase the risk score of a detected event?
Answer: The account is a highly privileged administrator account managed in the Vault
PTA weights events higher when the involved account holds elevated privileges, as compromise of such accounts carries greater organizational risk.
Which type of attack does PTA detect when it observes an account performing authentication using an NT hash instead of a plaintext password?
Answer: Pass-the-Hash
Pass-the-Hash attacks authenticate using the NT hash directly, bypassing the need for plaintext credentials, and PTA identifies this pattern.
What does PTA use to establish a behavioral baseline for privileged accounts?
Answer: Historical activity data collected over a learning period
PTA analyzes historical account behavior over a learning period to build baselines that allow it to identify deviations indicating threats.
A PTA alert shows 'Suspected DCSync attack.' What does this indicate?
Answer: An attacker is synchronizing Active Directory replication to extract all password hashes
A DCSync attack abuses AD replication protocols to pull password hashes for all domain accounts, effectively dumping the entire directory.
Which PTA feature allows security teams to review a timeline of all events associated with a specific privileged account after an alert fires?
Answer: Threat investigation view
PTA's threat investigation view provides a chronological timeline of account activity to help analysts understand the full scope of a detected threat.
Which network protocol activity does PTA primarily monitor to detect lateral movement between Windows hosts?
Answer: SMB and Kerberos authentication traffic
PTA monitors SMB and Kerberos traffic patterns to detect lateral movement techniques such as Pass-the-Hash and Pass-the-Ticket.