Quiz 2 Question 1 of 20

You are investigating logon events on a domain controller. A compromised workstation authenticates as a domain user using NTLMv2 network logons. The user has no interactive logon events on that workstation, yet several successful remote authentications occur. What authentication behavior is most likely occurring?

Select an answer to reveal the explanation.

Motivation