GPEN Domain Escalation and Persistence Practice Question
A penetration tester has obtained Domain Admin credentials during an internal engagement and wants to establish long-term persistence that survives a Domain Admin password reset and reboots. The tester needs a method that remains stealthy and does not rely on leaving a binary on disk. Which technique best meets these requirements?
⚠ Common exam trap
The trap here is assuming that any Domain Admin-level access survives a password reset; only techniques tied to the krbtgt hash or similar secrets withstand that specific remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a Golden Ticket by forging a Kerberos TGT using the krbtgt account hash.
A Golden Ticket is forged from the krbtgt hash and validated by the domain's Kerberos service until the krbtgt password is reset twice. This makes it resilient to Domain Admin password changes and reboots, and because it is generated on demand without a persistent binary, it is stealthier than account creation, new services, or ACL modifications. It directly satisfies the scenario's requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a Golden Ticket by forging a Kerberos TGT using the krbtgt account hash.
Why this is correct
A Golden Ticket is a forged TGT signed with the krbtgt account's NTLM hash. It remains valid until the krbtgt password is changed twice, so it survives normal Domain Admin password resets and reboots. Because it is generated on demand and not written to disk, it is stealthy and does not rely on a persistent binary, matching the scenario's constraints precisely.
- ✗
Install a service on a domain controller that runs as Local System and starts automatically.
Why it's wrong here
A new service on a domain controller is a noisy, on-disk artifact. Service creation events (7045) are commonly monitored, and the binary must be present and may be scanned by antivirus or EDR. It also does not inherently survive a Domain Admin password reset, and it lacks the stealth and no-disk-footprint properties required by the scenario.
- ✗
Create a new user account with Domain Admin membership and hide it from the default Users container.
Why it's wrong here
A new Domain Admin account is a high-visibility artifact. Account creation events (4720) and privileged group changes (4728) are logged by default on domain controllers and easily caught by SIEM rules or periodic access reviews. It also does not survive a thorough review and is not stealthy, failing the requirement to avoid obvious domain-level persistence.
- ✗
Add an ACL to the Domain Admins group granting Full Control to a controlled user account.
Why it's wrong here
Modifying the Domain Admins ACL is a persistent directory change that can be detected by ACL monitoring tools or a directory-sync review. While it may survive password resets, it is not stealthy and is an on-disk directory artifact. It also requires the controlled account to remain enabled, which is a clear indicator of compromise during a security audit.
Visual reference
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.