CAS-004 Security Operations Practice Question
A security analyst is reviewing a Windows event log from a domain controller and notices Event ID 4769 with the ticket encryption type 0x17. The analyst suspects a Kerberoasting attack. Which of the following best explains why this event is suspicious?
⚠ Common exam trap
Many candidates confuse encryption type 0x17 with AES, or misidentifying the event ID as a TGT request instead of a service ticket request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The encryption type 0x17 indicates RC4-HMAC, which is weak and often requested by attackers to crack service account passwords offline.
Kerberoasting involves requesting service tickets for accounts with SPNs and then cracking them offline. Attackers often request RC4 (0x17) encryption because it is weaker and faster to crack. Event ID 4769 with encryption type 0x17 on a domain controller is a key detection point. The correct answer identifies RC4-HMAC as the suspicious element, which aligns with known attacker tactics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The encryption type 0x17 indicates that the ticket is encrypted with the KRBTGT account hash, which is only used for TGTs and not service tickets.
Why it's wrong here
Service tickets are encrypted with the service account's hash, not the KRBTGT hash. The KRBTGT hash is used for TGTs. Encryption type 0x17 (RC4) can be used for both, but the use of KRBTGT is not indicated by the encryption type alone. This option incorrectly associates the encryption type with the KRBTGT account.
- ✗
The encryption type 0x17 indicates AES256-CTS-HMAC-SHA1-96, which is the default for modern Windows systems and should not trigger alerts.
Why it's wrong here
Encryption type 0x17 is actually RC4-HMAC, not AES256. AES256 corresponds to 0x12. If an analyst mistakenly believes 0x17 is AES, they would ignore a critical Kerberoasting indicator. This option misidentifies the encryption type and incorrectly suggests it is benign, which would lead to a missed detection.
- ✗
Event ID 4769 with encryption type 0x17 indicates a TGT request using DES, which is deprecated and signals an attempt to downgrade encryption.
Why it's wrong here
Event ID 4769 is for service ticket requests (TGS), not TGT requests (which is 4768). Also, 0x17 is RC4, not DES. DES encryption types are 0x1 and 0x3. This option confuses the event ID and encryption type, leading to an incorrect conclusion about a downgrade attack.
- ✓
The encryption type 0x17 indicates RC4-HMAC, which is weak and often requested by attackers to crack service account passwords offline.
Why this is correct
Event ID 4769 logs a Kerberos service ticket request. The encryption type 0x17 corresponds to RC4-HMAC, which is weaker and faster to crack than AES. Attackers performing Kerberoasting often request RC4-encrypted tickets for service accounts with SPNs, then extract and crack them offline. Thus, seeing RC4 where AES is expected is a strong indicator of Kerberoasting.
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.