PCNSC · Question #74
If the firewall is configured for credential phishing prevention using the "Domain Credential Filter" method, which login will be detected as credential theft?
The correct answer is A. Using the name user's corporate username and password. The Windows-based User-ID agent is installed on a Read-Only Domain Controller (RODC). The User-ID agent collects password hashes that correspond to users for which you want to enable credential detection and sends these mappings to the firewall. The firewall then checks if the…
Question
If the firewall is configured for credential phishing prevention using the "Domain Credential Filter" method, which login will be detected as credential theft?
Options
- AUsing the name user's corporate username and password.
- BFirst four letters of the username matching any valid corporate username.
- CMatching any valid corporate username.
- DMapping to the IP address of the logged-in user.
How the community answered
(22 responses)- A77% (17)
- B9% (2)
- C5% (1)
- D9% (2)
Explanation
The Windows-based User-ID agent is installed on a Read-Only Domain Controller (RODC). The User-ID agent collects password hashes that correspond to users for which you want to enable credential detection and sends these mappings to the firewall. The firewall then checks if the source IP address of a session matches a username and if the password submitted to the webpage belongs to that username. With this mode, the firewall blocks or alerts on the submission only when the password submitted matches a user password. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/url-filtering/prevent-credential- phishing/methods-to-check-for-corporate-credential-submissions
Topics
Community Discussion
No community discussion yet for this question.