Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

Which behavior is indicative of a 'Golden Ticket' attack occurring in a Windows environment?

⚠ Common exam trap

Candidates often overlook the lack of AS-REQ. They focus on the ticket itself rather than the fact that the ticket exists without a legitimate initial request to the KDC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unusually long ticket lifetimes or requests without an initial AS-REQ.

A Golden Ticket attack involves an adversary gaining access to the Krbtgt account hash, which allows them to forge TGTs (Ticket Granting Tickets) for any account. Because the ticket is forged offline and holds virtually infinite lifetime, it bypasses password changes and enables persistent, stealthy domain-wide access. Detecting this requires monitoring for abnormal TGT requests that do not correlate with legitimate authentication events, which is vital for preventing long-term domain compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user password is changed without authorization.

    Why it's wrong here

    Password changes are unrelated to Golden Ticket attacks. The essence of a Golden Ticket is that the attacker does not need the actual password of any user; they forge the TGT using the KRBTGT hash, rendering password changes useless against their forged credentials.

  • ✓

    Unusually long ticket lifetimes or requests without an initial AS-REQ.

    Why this is correct

    Golden tickets are forged with custom, often extremely long, lifetimes and are injected into the session without the standard Authentication Service Request (AS-REQ) phase. Observing these anomalies in Kerberos traffic is a primary indicator of a compromised domain controller or the use of forged tickets.

  • ✗

    An increase in NTLM traffic across the domain.

    Why it's wrong here

    Golden Ticket attacks are specific to the Kerberos protocol. While attackers may use NTLM for other purposes, the creation and use of a Golden Ticket are exclusively Kerberos-based activities. Therefore, monitoring NTLM traffic would not provide insight into a Golden Ticket incident.

  • ✗

    The creation of a new, highly privileged domain administrator.

    Why it's wrong here

    Golden Ticket attacks allow the attacker to impersonate any user, including domain admins, without actually creating a new account. Therefore, creating a new account is not a requirement for the attack and would actually be a noisy, unnecessary step that increases the risk of discovery.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.