GCFA Practice Question: Identification of Malicious and Normal Activity
Which indicator is most effective for identifying a 'Golden Ticket' attack during Kerberos-based authentication?
⚠ Common exam trap
Candidates look for account lockouts or failed logins, which are not characteristic of Golden Tickets. Golden Tickets use forged credentials, so they appear as legitimate, highly privileged, and persistent authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unusually long ticket lifetimes in the Kerberos ticket history.
A Golden Ticket is a forged Kerberos Ticket Granting Ticket (TGT) created with a compromised KRBTGT account hash. Because it is forged, it can grant the attacker unlimited access to any resource in the domain for long periods. Identifying this requires looking for tickets with unusually long lifetimes, or tickets that do not match the standard issuance patterns expected from the domain controller's authentication logs during normal operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Unusually long ticket lifetimes in the Kerberos ticket history.
Why this is correct
Golden Tickets are often created with extremely long expiration times, sometimes years into the future. Monitoring ticket lifetimes is a highly effective way to identify forged TGTs, as standard Kerberos tickets have strictly enforced, short lifetimes defined by domain policies that a forged ticket would likely bypass or violate.
- ✗
Multiple failed login attempts on a workstation.
Why it's wrong here
Failed logins are typically associated with brute-force attacks or credential stuffing, not Golden Ticket attacks. A Golden Ticket attack assumes the attacker already possesses the KRBTGT hash and can generate valid-looking tickets, thereby avoiding the need for noisy, repetitive login attempts that trigger account lockouts.
- ✗
An increase in web traffic on port 443.
Why it's wrong here
Port 443 is used for HTTPS traffic, which is unrelated to Kerberos authentication. Golden Ticket attacks occur at the identity level within the Windows authentication infrastructure, not through web protocol channels. This indicator would be entirely useless for detecting an identity-based exploit such as Kerberos ticket forgery.
- ✗
The presence of a new user account in Active Directory.
Why it's wrong here
Golden Ticket attacks use existing, privileged accounts to forge tickets; they do not require the creation of new AD objects. Looking for new accounts is a standard hygiene check but is not the specific indicator for detecting a forged TGT, which is an authentication-level anomaly within the existing infrastructure.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.