Quiz 15 Question 12 of 20

A SOC analyst is building a correlation rule to detect Golden Ticket attacks in Active Directory. Which Windows Security event sequence is most indicative of a Golden Ticket attack?

Select an answer to reveal the explanation.

Motivation