MS-102 Practice Question 3082

Exam: MS-102
Domain: Manage security and threats using Microsoft Defender XDR
Difficulty: medium
In Microsoft Defender for Identity, what type of threat is detected when an attacker steals a Kerberos Ticket Granting Ticket (TGT) from memory to impersonate administrative accounts?

Answer Options

A
Pass-the-Ticket (PtT)
B
Cross-Site Scripting (XSS)
C
SQL Injection
D
Buffer Overflow

Correct Answer

A: Pass-the-Ticket (PtT)

Explanation

Pass-the-Ticket (PtT) is a lateral movement and credential theft technique where attackers capture Kerberos TGTs to authenticate across network assets without passwords.