CAD Privileged Threat Analytics 2 — Questions and Answers
Question 1: Which data source does CyberArk PTA use to detect suspicious Kerberos activity such as Golden Ticket attacks?
- Windows Event Logs from domain controllers (Correct answer)
- NetFlow data from network switches
- Syslog from UNIX servers
- SNMP traps from routers
Correct answer: Windows Event Logs from domain controllers
PTA ingests Windows Event Logs from domain controllers to detect Kerberos anomalies like Golden Ticket and Pass-the-Ticket attacks.
Question 2: In CyberArk PTA, what does a 'suspected credential theft' alert typically indicate?
- A user changed their password more than twice in one day
- Credentials were extracted from memory using tools like Mimikatz (Correct answer)
- A vault account was checked out by an unauthorized user
- A privileged session was terminated unexpectedly
Correct answer: Credentials were extracted from memory using tools like Mimikatz
Suspected credential theft alerts in PTA indicate that credential extraction tools may have dumped passwords or hashes from memory.
Question 3: How does PTA classify accounts that are discovered performing privileged actions but are not managed by the CyberArk Vault?
- Orphaned accounts
- Unmanaged privileged accounts (Correct answer)
- Shadow accounts
- Rogue accounts
Correct answer: Unmanaged privileged accounts
PTA identifies and classifies accounts performing privileged activity without Vault management as unmanaged privileged accounts.
Question 4: When PTA detects a threat and automatically responds by rotating a compromised account's password, this capability is known as:
- Threat remediation
- Automatic response (Correct answer)
- Proactive protection
- Incident containment
Correct answer: Automatic response
PTA's automatic response feature triggers actions such as password rotation or account suspension when a threat is confirmed.
Question 5: Which PTA detection scenario identifies an attacker who has obtained a long-lived Kerberos ticket that does not expire normally?
- Pass-the-Hash
- Golden Ticket (Correct answer)
- Overpass-the-Hash
- Silver Ticket
Correct answer: Golden Ticket
A Golden Ticket attack forges a Kerberos TGT signed with the KRBTGT hash, producing a ticket with an abnormally long lifetime.
Question 6: What is the role of the PTA sensor deployed in the network?
- It stores encrypted vault credentials locally for offline access
- It captures and forwards network traffic metadata to the PTA server for analysis (Correct answer)
- It enforces session recording policies for RDP connections
- It synchronizes Active Directory group policies with the Vault
Correct answer: It captures and forwards network traffic metadata to the PTA server for analysis
The PTA sensor mirrors network traffic and forwards relevant metadata to the PTA server for behavioral and threat analysis.
Question 7: Which CyberArk component does PTA integrate with to automatically suspend a compromised privileged account?
- EPM (Endpoint Privilege Manager)
- PAM (Privileged Access Manager) / Vault (Correct answer)
- Conjur
- Identity (formerly Idaptive)
Correct answer: PAM (Privileged Access Manager) / Vault
PTA integrates with CyberArk PAM/Vault to execute automatic responses such as disabling or rotating accounts flagged as compromised.
Which data source does CyberArk PTA use to detect suspicious Kerberos activity such as Golden Ticket attacks?