MS-102 Practice Question 3082
Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: medium
In Microsoft Defender for Identity, what type of threat is detected when an attacker steals a Kerberos Ticket Granting Ticket (TGT) from memory to impersonate administrative accounts?
Answer Options
A
Pass-the-Ticket (PtT)
B
Cross-Site Scripting (XSS)
C
SQL Injection
D
Buffer Overflow
Correct Answer
A: Pass-the-Ticket (PtT)
Explanation
Pass-the-Ticket (PtT) is a lateral movement and credential theft technique where attackers capture Kerberos TGTs to authenticate across network assets without passwords.