>_ CYBERVERSE.AI
SOC Analyst interview question
How would you detect a Kerberos Golden Ticket attack?
What interviewers are really testing
- Knowledge of Kerberos artifacts and Event IDs
- Anomaly patterns: ticket lifetime, missing AS-REQ
- Remediation knowledge (KRBTGT double reset)
A strong answer framework
- Event 4769 anomalies: abnormal ticket lifetimes, missing PAC
- TGT renewals without a matching 4768 (AS-REQ)
- Anomalous 4624 logon types for privileged accounts
- Monitor KRBTGT reset events (4723/4724)
- Baseline normal ticket behavior per environment
Follow-ups you should be ready for
- Why rotate KRBTGT twice?
- Golden vs silver ticket differences?
More real SOC Analyst interview questions