GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
Which behavior is indicative of a 'Golden Ticket' attack occurring in a Windows environment?
⚠ Common exam trap
Candidates often overlook the lack of AS-REQ. They focus on the ticket itself rather than the fact that the ticket exists without a legitimate initial request to the KDC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unusually long ticket lifetimes or requests without an initial AS-REQ.
A Golden Ticket attack involves an adversary gaining access to the Krbtgt account hash, which allows them to forge TGTs (Ticket Granting Tickets) for any account. Because the ticket is forged offline and holds virtually infinite lifetime, it bypasses password changes and enables persistent, stealthy domain-wide access. Detecting this requires monitoring for abnormal TGT requests that do not correlate with legitimate authentication events, which is vital for preventing long-term domain compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user password is changed without authorization.
Why it's wrong here
Password changes are unrelated to Golden Ticket attacks. The essence of a Golden Ticket is that the attacker does not need the actual password of any user; they forge the TGT using the KRBTGT hash, rendering password changes useless against their forged credentials.
- ✓
Unusually long ticket lifetimes or requests without an initial AS-REQ.
Why this is correct
Golden tickets are forged with custom, often extremely long, lifetimes and are injected into the session without the standard Authentication Service Request (AS-REQ) phase. Observing these anomalies in Kerberos traffic is a primary indicator of a compromised domain controller or the use of forged tickets.
- ✗
An increase in NTLM traffic across the domain.
Why it's wrong here
Golden Ticket attacks are specific to the Kerberos protocol. While attackers may use NTLM for other purposes, the creation and use of a Golden Ticket are exclusively Kerberos-based activities. Therefore, monitoring NTLM traffic would not provide insight into a Golden Ticket incident.
- ✗
The creation of a new, highly privileged domain administrator.
Why it's wrong here
Golden Ticket attacks allow the attacker to impersonate any user, including domain admins, without actually creating a new account. Therefore, creating a new account is not a requirement for the attack and would actually be a noisy, unnecessary step that increases the risk of discovery.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.