Quiz 14 Question 7 of 20

A security analyst is building a detection for Kerberoasting in the SIEM using Windows Security event logs. Which Event ID indicates that a Kerberos service ticket was requested for an account with an SPN?

Select an answer to reveal the explanation.

Motivation