GPEN Kerberos Attacks Practice Question
A penetration tester has compromised a workstation and obtained a Kerberos TGT for a low-privileged domain user. The tester wants to abuse unconstrained delegation configured on a member server named APP01 to escalate privileges. Which two actions are required to achieve this? (Choose two.)
⚠ Common exam trap
The trap here is assuming the low-privileged user's own TGT is sufficient, when the attack depends on capturing a domain controller's TGT that is cached on the unconstrained delegation host.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Extract the cached TGT from APP01 and inject it into the tester's session for reuse.
Abusing unconstrained delegation requires forcing a high-value account, such as a domain controller, to authenticate to the delegation-enabled host so its TGT is cached, then extracting and reusing that TGT. Coercion techniques place the DC's TGT on APP01, and extraction tools enable impersonation, leading to domain compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Request a service ticket for the krbtgt account using the compromised user's TGT.
Why it's wrong here
The krbtgt account's key is not exposed through normal TGS requests, so a low-privileged user cannot obtain a usable service ticket for it. Forging a golden ticket requires the krbtgt hash, which is not available at this stage. This action does not leverage the unconstrained delegation misconfiguration.
- ✓
Extract the cached TGT from APP01 and inject it into the tester's session for reuse.
Why this is correct
Once the domain controller's TGT is cached on APP01, extracting it with a tool such as Rubeus or Mimikatz and injecting it into the tester's session allows the tester to impersonate the DC. Presenting that TGT yields a service ticket with domain controller privileges, enabling DCSync or other high-impact actions.
- ✗
Disable Kerberos pre-authentication on the compromised user account to facilitate ticket capture.
Why it's wrong here
Disabling pre-authentication affects AS-REP Roasting and requires account modification rights the tester lacks. It does not influence how unconstrained delegation caches TGTs on APP01. This action is unrelated to the delegation abuse path and would not yield the domain controller's TGT.
- ✓
Coerce a domain controller to authenticate to APP01 so its TGT is captured in memory.
Why this is correct
Unconstrained delegation causes any service on APP01 to receive and cache the TGT of users who authenticate to it, including domain controllers. Coercing a DC to authenticate, for example via PrinterBug or PetitPotam, places the DC's TGT into APP01's LSASS cache. That cached TGT is then available for extraction and reuse, enabling privilege escalation.
- ✗
Modify the msDS-AllowedToDelegateTo attribute on APP01 to include the domain controller.
Why it's wrong here
Altering msDS-AllowedToDelegateTo configures constrained delegation and requires directory modification privileges the tester does not possess with a low-privileged account. The scenario focuses on abusing existing unconstrained delegation, which does not rely on that attribute. Attempting this fails due to insufficient rights and is unnecessary.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.