Privileged Threat Analytics Flashcards
7 cards from real CAD practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Privileged Threat Analytics flashcards as text
What is Kerberoasting, and how does PTA detect it?
Answer: Requesting service tickets for SPNs to crack offline; PTA detects unusual TGS request volumes for service accounts
Kerberoasting requests TGS tickets for service accounts to crack offline; PTA detects spikes in TGS requests targeting service principal names.
When configuring PTA integration with the CyberArk Vault, which credential is used by PTA to authenticate to the Vault API?
Answer: A dedicated CyberArk user account provisioned for PTA with least-privilege permissions
PTA authenticates to the Vault using a dedicated service account provisioned with only the permissions required for PTA's integration tasks.
Which PTA alert category covers scenarios where a privileged account logs into an atypical machine it has never accessed before?
Answer: Abnormal behavior - new machine access
PTA's behavioral analytics flag access to machines outside the account's established baseline as abnormal new machine access.
What happens to a PTA security event after an administrator marks it as a 'False Positive'?
Answer: The event is closed and PTA uses the feedback to refine its detection model
Marking an event as a false positive closes it and provides feedback that helps PTA tune its behavioral models to reduce future false positives.
In CyberArk PTA, what is the purpose of the 'Risky Activity' alert type?
Answer: To identify privileged actions performed outside of approved time windows or from unexpected locations
Risky Activity alerts capture privileged account behaviors that deviate from established patterns, such as off-hours access or unusual source locations.
Which SIEM platforms does CyberArk PTA natively support for forwarding security events?
Answer: Splunk and IBM QRadar, with syslog-based forwarding for others
PTA provides native integrations for Splunk and QRadar and supports syslog-based CEF/LEEF forwarding for other SIEM platforms.
What is an 'AS-REP Roasting' attack, and how does PTA help detect accounts vulnerable to it?
Answer: Attacking accounts with no Kerberos pre-authentication required, allowing hash capture without credentials; PTA identifies such accounts
AS-REP Roasting targets accounts with Kerberos pre-authentication disabled; PTA can identify these unprotected privileged accounts in its discovery findings.