Valid CAS-005 Dumps shared by ExamDiscuss.com for Helping Passing CAS-005 Exam! ExamDiscuss.com now offer the newest CAS-005 exam dumps, the ExamDiscuss.com CAS-005 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com CAS-005 dumps with Test Engine here:
After a penetration test on the internal network, the following report was generated: Attack Target Result Compromised host ADMIN01S.CORP.LOCAL Successful Hash collected KRBTGT.CORP.LOCAL Successful Hash collected SQLSV.CORP.LOCAL Successful Pass the hash SQLSV.CORP.LOCAL Failed Domain control CORP.LOCAL Successful Which of the following should be recommended to remediate the attack?
Correct Answer: C
Comprehensive and Detailed Explanation: The attacker gained domain control by collecting the KRBTGT hash (used for Kerberos tickets). Let's evaluate: * A. Deleting SQLSV:Irrelevant since pass-the-hash failed there. * B. Reimaging ADMIN01S:Addresses the compromised host but not domain control. * C. Rotating KRBTGT password:Invalidates stolen Kerberos tickets, mitigating domain control per CAS- 005's focus on identity security. Reference:CompTIA SecurityX (CAS-005) objectives, Domain 2: Security Operations, covering Kerberos security.