A penetration test has demonstrated that domain administrator accounts were vulnerable to pass-the-hash attacks. Which of the following would have been the best strategy to prevent the threat actor from using domain administrator accounts?
Choose an answer
Tap an option to check your answer.
Correct answer: Implement a privileged access management solution..
Why this is the answer
Implementing a Privileged Access Management (PAM) solution is the best strategy because it specifically addresses the security of privileged accounts, like domain administrators, by controlling, monitoring, and auditing their access. PAM solutions can enforce strong authentication, just-in-time access, and session recording, significantly reducing the attack surface for pass-the-hash and other credential theft attacks. Auditing accounts for password compliance is good practice but doesn't prevent pass-the-hash if the hash is compromised. Creating IDS policies monitors access but is a reactive measure; it doesn't prevent the attack. Enforcing password expiration is also a good general security practice but doesn't directly mitigate pass-the-hash vulnerabilities, as the hash can still be used even if the password has expired or is soon to expire.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed