A security administrator receives an alert from Microsoft Defender for Identity about a suspicious Kerberos ticket request from a domain controller. The alert suggests a possible Golden Ticket attack. Which action should the administrator take to validate the alert?
Checking the domain controller's Security event log for Event ID 4769 is the correct validation step because this event records every Kerberos service ticket request. In a Golden Ticket attack, the attacker uses a forged TGT to request service tickets, so Event ID 4769 entries will show anomalies such as unusual encryption types (e.g., RC4 when AES is expected), unexpected service names, or client IP addresses that don't align with normal behavior. These anomalies confirm that a forged ticket is being presented.
Why this answer
Event ID 4769 (Kerberos Service Ticket Request) on a domain controller is the authoritative source for validating suspicious ticket requests. In a Golden Ticket attack, the forged ticket often exhibits anomalous attributes such as an unusually long lifetime, a non-existent or disabled user account, or encryption type mismatches (e.g., RC4 when AES is expected). Reviewing this log directly confirms whether the ticket characteristics deviate from normal Kerberos behavior, providing definitive evidence for the alert.
Exam trap
The trap here is that candidates confuse validation steps with remediation actions, specifically choosing to reset the krbtgt password (Option C) before confirming the attack through log analysis, which would destroy forensic evidence and fail to validate the alert.
How to eliminate wrong answers
Option A is wrong because brute force attempts relate to password guessing or credential stuffing, not the validation of a forged Kerberos ticket; Golden Ticket attacks involve forged TGTs, not repeated authentication failures. Option C is wrong because resetting the krbtgt account password twice is a remediation step to invalidate existing Golden Tickets after an attack is confirmed, not a validation action to determine if the alert is legitimate. Option D is wrong because while a disabled user account might be a clue, it is not a definitive validation step; the ticket could be forged for an enabled account, and the primary validation requires examining the Kerberos service ticket request details in Event ID 4769.