You must map an observed Kerberos condition to the correct attack: AS-REP roasting, Kerberoasting, Silver/Golden Ticket, or delegation abuse. The critical skill is distinguishing which ticket type and hash source each scenario implies before choosing a tool or command.
Start practicing
Kerberos Attacks — choose a session length
Free · No account required
Domain overview
This domain covers abusing Kerberos authentication in Windows Active Directory: pre-auth weaknesses, ticket forgery, delegation misconfigurations, and service account cracking. GPEN questions present traffic captures, extracted hashes, or account attributes and require you to select the correct attack, tool, or defensive control rather than recall theory alone.
Exam objectives
Identifying AS-REP roasting when DONT_REQ_PREAUTH is set and extracting crackable hashes with GetNPUsers or Rubeus.
Forging Silver and Golden Tickets using service or krbtgt NTLM hashes, including PAC and SID manipulation.
Exploiting unconstrained, constrained, and resource-based constrained delegation via S4U2Self and S4U2Proxy.
Kerberoasting service accounts with SPNs using GetUserSPNs or Rubeus and cracking with Hashcat mode 13100.
Confusing AS-REP roasting (no pre-auth required) with Kerberoasting (requires SPN and TGS request), leading to wrong tool selection.
Assuming a Silver Ticket grants domain-wide access; it is scoped to the targeted service and its host, not the whole domain.
Forgetting that gMSAs rotate passwords automatically, so Kerberoasting yields no crackable material for those accounts.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?
2Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?
3What is the primary security benefit of implementing Group Managed Service Accounts (gMSAs) in an environment vulnerable to Kerberoasting?
4What is the fundamental difference between Golden Ticket and Silver Ticket attacks?
5Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?
6Which Kerberos feature is specifically exploited when an attacker uses 'constrained delegation' to escalate privileges?
7What is the primary risk associated with 'Unconstrained Delegation' in Active Directory?
8What is the primary objective of a 'Kerberos Armoring' (FAST) implementation?
9Which of the following describes the 'AS-REP Roasting' attack?
10A penetration tester has obtained a low-privileged domain user's cleartext credentials. During reconnaissance, the tester wants to enumerate which accounts in the domain are configured with Service Principal Names (SPNs) and are therefore candidates for Kerberoasting, without triggering a lockout or modifying the directory. Which of the following approaches best accomplishes this?
11During a penetration test, an operator compromises a workstation where a domain administrator has an active logon session. The operator wants to extract the domain administrator's Kerberos TGT from LSASS and reuse it to access other systems without knowing the administrator's password. Which of the following techniques is specifically designed for this purpose?
12A penetration tester is reviewing Active Directory for Kerberos delegation misconfigurations that could allow privilege escalation. Which of the following TWO configurations should the tester flag as directly enabling an attacker to impersonate a domain administrator to a target service? (Choose two.)
13During an internal assessment, a tester has valid domain credentials for a standard user and captures Kerberos traffic with Wireshark. The tester notices several TGS-REQ packets for service principal names ending in "/MSSQLSvc" across multiple hosts. The tester wants to identify which accounts are vulnerable to offline password cracking without triggering account lockouts. Which action should the tester take next?
14A penetration tester has compromised a workstation and obtained a Kerberos TGT for a low-privileged domain user. The tester wants to abuse unconstrained delegation configured on a member server named APP01 to escalate privileges. Which two actions are required to achieve this? (Choose two.)
15During an internal penetration test, you have obtained cleartext credentials for a low-privileged Active Directory user. You want to enumerate which user accounts do not require Kerberos preauthentication so you can request AS-REP messages and crack them offline. Which Impacket tool and command should you use?
16You have compromised a workstation and extracted the NTLM hash of a service account that is configured for unconstrained delegation. You want to craft a Silver Ticket to impersonate a domain administrator when accessing a specific file server. Which piece of information is absolutely required to forge this ticket?
17A penetration tester is reviewing Kerberos traffic and notices that a user account has the DONT_REQ_PREAUTH flag set in its userAccountControl attribute. The tester wants to obtain crackable material for this account without any domain credentials. Which technique should the tester use?
18You are performing a Kerberoasting attack against a domain. After requesting service tickets for accounts with SPNs, you extract the tickets and attempt to crack them offline. Which two factors most directly determine the success of cracking these tickets? (Choose two.)
19During a penetration test, a tester compromises a workstation and extracts a Kerberos TGT for a domain user from memory. The tester wants to use this TGT to access a file share on a remote server without knowing the user's password. Which action should the tester take?
20A penetration tester is analyzing a Kerberos attack that involved forging a ticket to gain access to a specific server. The ticket was encrypted with the server's machine account hash and did not involve communication with the domain controller. Which type of attack does this describe?
You must map an observed Kerberos condition to the correct attack: AS-REP roasting, Kerberoasting, Silver/Golden Ticket, or delegation abuse. The critical skill is distinguishing which ticket type and hash source each scenario implies before choosing a tool or command.
The Courseiva GPEN question bank contains 20 questions in the Kerberos Attacks domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Kerberos Attacks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included