GCIH Network and Log Investigations Practice Question
During an investigation of a suspected lateral movement attempt within an Active Directory environment, an incident handler needs to isolate authentication events involving Kerberos ticket-granting service (TGS) requests that indicate potential Kerberoasting activity. Which Windows Security Event Log ID should the analyst examine to identify abnormal requests for service principal names (SPNs) using weak encryption algorithms?
⚠ Common exam trap
Many analysts confuse Event ID 4768, which tracks Ticket Granting Ticket (TGT) requests during initial authentication, with Event ID 4769, which tracks Service Ticket (TGS) requests used specifically for Kerberoasting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security Event ID 4769
Windows Security Event Log ID 4769 is generated whenever a Kerberos service ticket is requested. By filtering for Event ID 4769 and analyzing the encryption type field, analysts can spot requests using older, weaker encryption standards like RC4, which are heavily utilized during offline Kerberoasting password cracking attacks against service accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security Event ID 4624
Why it's wrong here
Event ID 4624 logs successful logon sessions, capturing account, logon type and source, but never TGS ticket requests or their encryption types. It is tempting because 4624 is the standard logon-audit event, which would be correct for establishing when and how an account authenticated rather than for spotting Kerberoasting.
- ✗
Security Event ID 4768
Why it's wrong here
Event ID 4768 records Kerberos authentication service (TGT) requests, issued by the domain controller's AS, not TGS service-ticket requests. It is tempting because 4768 is Kerberos ticket-related and reveals encryption downgrades, which would be correct when investigating AS-REP roasting rather than Kerberoasting.
- ✗
Security Event ID 4771
Why it's wrong here
Event ID 4771 records Kerberos pre-authentication failures, typically from bad passwords or locked accounts, not TGS requests for service tickets. It is tempting because 4771 is Kerberos-related and useful for brute-force detection, which would be the right choice when investigating failed logon attempts rather than Kerberoasting.
- ✓
Security Event ID 4769
Why this is correct
Event ID 4769 is logged for Kerberos service ticket (TGS) requests, recording the account, requested SPN and encryption type. Filtering for weak RC4 encryption and abnormal SPN requests exposes Kerberoasting, where attackers request service tickets to crack service account passwords offline.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.