GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
During an incident response engagement, an analyst is reviewing Windows security event logs from a domain controller. The analyst observes a series of Event ID 4769 (A Kerberos service ticket was requested) entries with encryption type 0x17 (RC4-HMAC) for multiple service accounts, originating from a single workstation within a short time frame. Which of the following best describes the attacker's activity and the appropriate detection focus?
⚠ Common exam trap
The trap here is assuming that any Kerberos service ticket request with RC4 encryption indicates an attack, when in fact RC4 may be legitimately used; the key is the anomalous pattern of multiple requests from one source in a short time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kerberoasting; detection should focus on the service account names and the requesting user account, as the attacker is likely using a compromised user account to request service tickets for offline cracking.
The burst of Event ID 4769 entries with RC4 encryption for multiple service accounts from a single workstation is a classic indicator of Kerberoasting, where an attacker requests service tickets for offline password cracking. Detection should correlate the requesting user account and targeted service accounts to identify the compromised account and affected services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Kerberoasting; detection should focus on the service account names and the requesting user account, as the attacker is likely using a compromised user account to request service tickets for offline cracking.
Why this is correct
Kerberoasting involves requesting service tickets for accounts with SPNs and cracking them offline. Event ID 4769 with RC4 encryption from a single workstation for multiple service accounts is a strong indicator. The detection should correlate the requesting user and the targeted service accounts to identify the compromised account and affected services.
- ✗
Golden Ticket attack; detection should focus on the domain controller's Kerberos ticket-granting ticket (TGT) issuance and the encryption type, as the attacker is forging TGTs.
Why it's wrong here
A Golden Ticket attack involves forging a TGT using the KRBTGT account hash. This would typically generate Event ID 4768 (TGT request) or 4769 for service tickets with abnormal lifetimes or encryption, but a burst of RC4 service ticket requests for multiple SPNs from one workstation is not characteristic. Golden Ticket detection focuses on TGT anomalies, not service ticket request patterns.
- ✗
Pass-the-Ticket; detection should focus on the source IP address and the ticket lifetime, as the attacker is reusing a stolen ticket to authenticate to multiple services.
Why it's wrong here
Pass-the-Ticket involves using a stolen Kerberos ticket to authenticate. While Event ID 4769 is generated, it would not typically show a burst of RC4-encrypted service ticket requests for multiple service accounts from one workstation. Pass-the-Ticket would more likely show anomalous logon events (e.g., 4624) with a ticket, not a pattern of service ticket requests.
- ✗
Silver Ticket attack; detection should focus on the service account's password hash and the service ticket's encryption type, as the attacker is forging service tickets.
Why it's wrong here
A Silver Ticket attack involves forging a service ticket using the service account's password hash. It would not generate Event ID 4769 on the domain controller because the ticket is forged and presented directly to the service, bypassing the KDC. The presence of 4769 events indicates the KDC was involved, so this is not a Silver Ticket attack.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.