Courseiva

GCIH Network and Log Investigations Practice Question

During an investigation of a suspected lateral movement attempt within an Active Directory environment, an incident handler needs to isolate authentication events involving Kerberos ticket-granting service (TGS) requests that indicate potential Kerberoasting activity. Which Windows Security Event Log ID should the analyst examine to identify abnormal requests for service principal names (SPNs) using weak encryption algorithms?

⚠ Common exam trap

Many analysts confuse Event ID 4768, which tracks Ticket Granting Ticket (TGT) requests during initial authentication, with Event ID 4769, which tracks Service Ticket (TGS) requests used specifically for Kerberoasting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Event ID 4769

Windows Security Event Log ID 4769 is generated whenever a Kerberos service ticket is requested. By filtering for Event ID 4769 and analyzing the encryption type field, analysts can spot requests using older, weaker encryption standards like RC4, which are heavily utilized during offline Kerberoasting password cracking attacks against service accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Event ID 4624

    Why it's wrong here

    Event ID 4624 logs successful logon sessions, capturing account, logon type and source, but never TGS ticket requests or their encryption types. It is tempting because 4624 is the standard logon-audit event, which would be correct for establishing when and how an account authenticated rather than for spotting Kerberoasting.

  • ✗

    Security Event ID 4768

    Why it's wrong here

    Event ID 4768 records Kerberos authentication service (TGT) requests, issued by the domain controller's AS, not TGS service-ticket requests. It is tempting because 4768 is Kerberos ticket-related and reveals encryption downgrades, which would be correct when investigating AS-REP roasting rather than Kerberoasting.

  • ✗

    Security Event ID 4771

    Why it's wrong here

    Event ID 4771 records Kerberos pre-authentication failures, typically from bad passwords or locked accounts, not TGS requests for service tickets. It is tempting because 4771 is Kerberos-related and useful for brute-force detection, which would be the right choice when investigating failed logon attempts rather than Kerberoasting.

  • ✓

    Security Event ID 4769

    Why this is correct

    Event ID 4769 is logged for Kerberos service ticket (TGS) requests, recording the account, requested SPN and encryption type. Filtering for weak RC4 encryption and abnormal SPN requests exposes Kerberoasting, where attackers request service tickets to crack service account passwords offline.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.