A library’s compromise-recovery plan for Active Directory never mentions the krbtgt account password. What recovery-hygiene point should the tester emphasize?
Select an answer to reveal the explanation.
Short Explanation
Think of krbtgt as the master stamp that makes domain tickets look official. After a real domain compromise scare, recovery talk has to include how that stamp gets replaced — not just patching a few desktops. Skipping krbtgt in the recovery plan leaves a hole in the hygiene checklist.
Full Explanation
The krbtgt account is central to Kerberos ticket granting in Active Directory. In suspected domain-compromise recovery planning, organizations discuss controlled krbtgt password reset procedures as part of restoring trust in ticket issuance. Framing krbtgt as a print spooler or claiming only local SAM hashes matter misstates AD recovery priorities. Assessors should note missing krbtgt hygiene in recovery plans as an awareness finding — without providing attack how-tos.