ATA resides on-premises and protects you from internal threats and cyber attacks. You can deploy it by using port mirroring from your domain controllers to the ATA gateway (on its own server) or by deploying a lightweight gateway (LGW) directly on the domain controllers.
ATA can detect anomalous logins, password sharing, sensitive group changes, malicious attacks from known attack types, weak protocols, and more.
One type of attack that you may see in the exam is a pass-the-hash attack, in which the attacker uses the underlying hash behind an account's password to authenticate to computers, rather than needing the plain-text password itself. You might suspect this if you were alerted to a user authenticating to machines they wouldn't normally (anomalous behavior). To remediate this, you'd change the user's password, but any Kerberos...