QuestionQ739

SMB Security

An organization has enabled registry-based local account token filtering on its workstations. What further action must it take to protect against pass-the-hash attacks?

  • A Remove active command prompts
  • B Disable the local administrator account
  • C Disable null sessions on the domain
  • D Block outbound access to TCP port 139
Explanation

Disabling the built-in local Administrator account makes that account unavailable for pass-the-hash and other credential-theft attacks. Local-account token filtering restricts remote administrative tokens, while disabling the account removes a commonly targeted local administrative credential from use.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!