Question: A tester was able to leverage a pass-the-hash attack during a recent penetration test. The tester gained a foothold and moved laterally through the network.
A tester was able to leverage a pass-the-hash attack during a recent penetration test. The tester gained a foothold and moved laterally through the network. Which of the following would prevent this type of attack from reoccurring?
- Renaming all active service accounts and disabling all inactive service accounts
- Creating separate accounts for privileged access that are not used to log on to local machines
- Enabling full-disk encryption on all workstations that are used by administrators and disabling RDP
- Increasing the password complexity requirements and setting account expiration dates.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
