GPEN Kerberos Attacks Practice Question
A penetration tester is analyzing a Kerberos attack that involved forging a ticket to gain access to a specific server. The ticket was encrypted with the server's machine account hash and did not involve communication with the domain controller. Which type of attack does this describe?
⚠ Common exam trap
Many exam-takers confuse Silver Tickets with Golden Tickets; both are forged, but Silver Tickets target a specific service and use the service's key, while Golden Tickets target the domain and use the krbtgt key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Silver Ticket
A Silver Ticket is a forged service ticket encrypted with the target service's key, allowing access without contacting the DC. Golden Tickets are forged TGTs encrypted with the krbtgt hash. Kerberoasting and AS-REP Roasting involve requesting legitimate tickets for offline cracking, not forging. Thus, the description matches a Silver Ticket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Silver Ticket
Why this is correct
A Silver Ticket is a forged service ticket (TGS) encrypted with the target service account's hash, such as a machine account hash for a server. It does not require communication with the domain controller because the service decrypts the ticket with its own key and trusts the embedded PAC. This matches the description of gaining access to a specific server without DC interaction.
- ✗
Golden Ticket
Why it's wrong here
A Golden Ticket is a forged TGT encrypted with the krbtgt account's hash. It allows access to any service in the domain and requires communication with the KDC for service ticket requests (though the TGT itself is forged). This scenario specifies encryption with the server's machine account hash and no DC communication, which does not match a Golden Ticket.
- ✗
AS-REP Roasting
Why it's wrong here
AS-REP Roasting targets accounts without Kerberos preauthentication and involves requesting an AS-REP to crack the user's password offline. It does not involve forging a service ticket or accessing a server directly. The scenario describes a forged ticket used for access, which is not part of AS-REP Roasting.
- ✗
Kerberoasting
Why it's wrong here
Kerberoasting involves requesting a legitimate service ticket for an account with an SPN and then cracking its encryption offline to recover the service account's password. It does not involve forging a ticket; the ticket is legitimate and issued by the KDC. The scenario describes a forged ticket, not a cracking attack, so Kerberoasting is incorrect.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.