Courseiva
Attacking Passwords →mediumMultiple Choice

GCIH Attacking Passwords Practice Question

An incident handler is reviewing compromised Active Directory domain credentials and notices that an attacker successfully recovered the cleartext password of a service account using an offline cracking tool. Which specific technique did the attacker most likely leverage to target this non-user domain object?

⚠ Common exam trap

Candidates often confuse Kerberoasting with AS-REP Roasting; however, AS-REP Roasting targets user accounts configured with pre-authentication disabled, whereas Kerberoasting specifically targets service accounts possessing assigned Service Principal Names.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kerberoasting by requesting a service ticket for an SPN and cracking it offline.

Kerberoasting allows any authenticated domain user to request a Service Principal Name ticket, extract the service ticket encrypted with the target service account's NTLM hash, and crack it offline without generating account lockout events. This represents a primary threat for enterprise service accounts utilizing weak passwords.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AS-REP Roasting targeting user accounts with Kerberos pre-authentication disabled.

    Why it's wrong here

    AS-REP Roasting targets user accounts lacking Kerberos pre-authentication, returning a ticket encrypted with the user's key; service accounts are non-user objects whose passwords are cracked from Kerberoasting service tickets. It tempts because both are offline Kerberos cracking techniques against domain accounts.

  • ✗

    NTLM relaying against local SMB signing configurations.

    Why it's wrong here

    NTLM relaying captures authentication traffic to impersonate a host; it does not extract a stored hash for offline cracking, and SMB signing configuration is unrelated to recovering cleartext from a service account. It tempts because relaying also targets service accounts, but the stem specifies offline cracking of a recovered hash.

  • ✗

    Pass-the-Hash utilizing harvested NTLM password hashes from memory.

    Why it's wrong here

    Pass-the-Hash reuses an NTLM hash for authentication without ever recovering cleartext, so it cannot explain a cracked plaintext password. It is tempting because it targets service accounts and non-user objects, and would be correct had the attacker authenticated with the hash rather than cracking it offline.

  • ✓

    Kerberoasting by requesting a service ticket for an SPN and cracking it offline.

    Why this is correct

    Kerberoasting leverages any standard domain user account to request a service ticket for an arbitrary Service Principal Name, allowing attackers to export the ticket and crack the underlying service account password completely offline.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.