Courseiva
Kerberos Attacks →mediumMultiple Choice

GPEN Kerberos Attacks Practice Question

A penetration tester has obtained a low-privileged domain user's cleartext credentials. During reconnaissance, the tester wants to enumerate which accounts in the domain are configured with Service Principal Names (SPNs) and are therefore candidates for Kerberoasting, without triggering a lockout or modifying the directory. Which of the following approaches best accomplishes this?

⚠ Common exam trap

Watch out — candidates often confuse AS-REP Roasting (accounts without pre-authentication) with Kerberoasting (accounts with SPNs), which are entirely different account configurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a targeted LDAP query for objects where servicePrincipalName is present and not null, using tools such as GetUserSPNs.py or PowerView's Get-DomainUser -SPN.

Kerberoasting requires identifying domain accounts that have a servicePrincipalName set, because those accounts can have a service ticket requested and cracked offline. The cleanest way to find them is a read-only LDAP search filtering on servicePrincipalName. This technique uses only legitimate authenticated access, avoids lockout risk, and does not alter the directory, making it the appropriate reconnaissance step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform an SMB null session against each domain controller and parse the SAM database for accounts ending in the $ suffix.

    Why it's wrong here

    SMB null sessions against modern domain controllers are disabled by default and cannot read the SAM database, which in any case contains local accounts, not domain service accounts. Accounts ending in $ are computer accounts, not necessarily Kerberoastable. This approach neither enumerates SPNs nor works against current Windows Server defaults.

  • ✓

    Run a targeted LDAP query for objects where servicePrincipalName is present and not null, using tools such as GetUserSPNs.py or PowerView's Get-DomainUser -SPN.

    Why this is correct

    Querying the directory for objects with a non-null servicePrincipalName attribute returns exactly the accounts eligible for Kerberoasting. This read-only LDAP operation requires only standard authenticated access, does not modify the directory, and does not generate failed logon events that could cause lockouts, making it the correct enumeration technique in this scenario.

  • ✗

    Send an AS-REQ for every account in the domain and inspect which accounts return a pre-authentication error versus a valid AS-REP.

    Why it's wrong here

    Sending AS-REQs for every account is AS-REP Roasting enumeration, which identifies accounts with Kerberos pre-authentication disabled, not accounts with SPNs. It does not reveal servicePrincipalName configuration, and mass AS-REQ attempts can generate noise and lockout risk. This approach answers a different question than the one posed.

  • ✗

    Request a TGS for the krbtgt service and inspect the returned ticket's encryption type to infer which accounts have SPNs.

    Why it's wrong here

    Requesting a TGS for krbtgt targets the Key Distribution Center service, not user or computer accounts with SPNs. The encryption type of a krbtgt ticket reveals nothing about which domain accounts are configured with servicePrincipalName values. This technique does not enumerate Kerberoastable accounts and may be flagged as anomalous behavior.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.