Courseiva
Security Monitoring →hardMultiple Select

200-201 Security Monitoring Practice Question

An analyst is correlating telemetry after a suspected Kerberoasting attack against an Active Directory environment. Which two artifacts, when found together, most strongly support that the attack succeeded in obtaining crackable service ticket material? (Choose two.)

⚠ Common exam trap

The trap here is pairing any credential-related anomaly, such as failed logons, with ticket activity, when Kerberoasting requires no password guessing and produces successful ticket requests instead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Security event 4769 logged with RC4 encryption type (0x17) for service accounts, generated in a short burst from one workstation.

Kerberoasting requires two observable steps: discovery of accounts with service principal names, and requests for their service tickets using weak encryption that can be cracked offline. A workstation issuing broad LDAP queries for the servicePrincipalName attribute, followed by a burst of event 4769 entries with RC4 encryption for service accounts, together demonstrate both steps. Failed logons or policy changes do not evidence ticket acquisition, and share access belongs to a different attack phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Windows Security event 4769 logged with RC4 encryption type (0x17) for service accounts, generated in a short burst from one workstation.

    Why this is correct

    Event 4769 records Kerberos service ticket requests. A burst of requests for multiple service principal names using RC4, the weaker encryption type, from a single non-server host matches the Kerberoasting pattern, since the attacker requests tickets and cracks them offline. The volume, encryption downgrade, and unusual requesting host together distinguish this from normal service access.

  • ✗

    A Group Policy update pushed to all domain-joined computers changing the minimum password length requirement.

    Why it's wrong here

    A Group Policy password length change is an administrative configuration event unrelated to Kerberos ticket abuse. Kerberoasting targets the encryption and cracking of service tickets, not password policy. Observing this policy event provides no evidence that service ticket material was requested or obtained, so it cannot corroborate the attack hypothesis even if it occurred during the same window.

  • ✓

    LDAP search traffic enumerating accounts with a servicePrincipalName attribute set, originating from a workstation rather than a domain controller.

    Why this is correct

    Kerberoasting begins by enumerating accounts that have service principal names, because those accounts can be issued service tickets. A workstation performing broad LDAP searches for the servicePrincipalName attribute is abnormal, since domain controllers and management tools normally perform such queries. This discovery step, paired with the ticket requests, establishes the full attack sequence rather than an isolated anomaly.

  • ✗

    A spike in Windows Security event 4625 failed logons against many user accounts from a single source over a brief interval.

    Why it's wrong here

    Event 4625 records failed authentication attempts and is characteristic of password spraying or brute force against accounts. Kerberoasting does not require guessing user passwords; it requests service tickets using an already authenticated session and cracks them offline. A failed-logon spike therefore points to a different technique and does not support the conclusion that crackable service ticket material was obtained.

  • ✗

    A sudden increase in SMB file share access to the finance department's documents from a user in the engineering group.

    Why it's wrong here

    Anomalous SMB share access suggests possible lateral movement or data collection, a different phase of an intrusion. Kerberoasting specifically concerns obtaining and cracking Kerberos service tickets, which occurs before or independently of file share access. While both could appear in one campaign, this artifact does not evidence crackable ticket material and therefore does not satisfy the question's requirement.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.