Courseiva
Kerberos Attacks →mediumMultiple Select

GPEN Kerberos Attacks Practice Question

A penetration tester is reviewing Active Directory for Kerberos delegation misconfigurations that could allow privilege escalation. Which of the following TWO configurations should the tester flag as directly enabling an attacker to impersonate a domain administrator to a target service? (Choose two.)

⚠ Common exam trap

The trap here is treating any delegation flag as exploitable, when only specific combinations like unconstrained delegation with a privileged logon or constrained delegation with protocol transition to a sensitive service actually enable impersonation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A user account configured for constrained delegation with the 'Use any authentication protocol' option and msDS-AllowedToDelegateTo set to a sensitive service.

Unconstrained delegation caches TGTs of authenticating users, so a domain administrator's logon on such a host exposes their TGT for impersonation. Constrained delegation with protocol transition and a sensitive target allows an attacker controlling the delegating account to impersonate any user, including administrators, to that service. Both configurations directly enable the described escalation and should be flagged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A standard user account with the 'Account is sensitive and cannot be delegated' flag set.

    Why it's wrong here

    The 'sensitive and cannot be delegated' flag prevents the account's credentials from being delegated, which is a hardening measure rather than a vulnerability. It actually blocks the escalation described, so it should not be flagged as enabling impersonation. This option is the opposite of a misconfiguration.

  • ✓

    A user account configured for constrained delegation with the 'Use any authentication protocol' option and msDS-AllowedToDelegateTo set to a sensitive service.

    Why this is correct

    Constrained delegation with protocol transition allows the service to obtain a forwardable ticket to any listed service on behalf of any user, without that user authenticating. If the allowed service is sensitive, an attacker controlling the account can impersonate a domain administrator to that service, achieving escalation.

  • ✗

    A group Managed Service Account (gMSA) with a 120-character automatically rotated password.

    Why it's wrong here

    Group Managed Service Accounts have long, complex, automatically rotated passwords managed by the domain, making them resistant to cracking and credential theft. They do not by themselves provide a delegation-based impersonation path. This is a secure configuration, not a misconfiguration to flag.

  • ✗

    A domain controller configured with the 'Trusted for Delegation' flag but no users currently logged on.

    Why it's wrong here

    A domain controller being trusted for delegation is normal and expected for replication and other functions. Without a user logged on and without the attacker having control of the DC, this configuration alone does not enable impersonation. The scenario requires a direct escalation path, which this does not provide.

  • ✓

    A computer account configured for unconstrained delegation where a domain administrator has authenticated.

    Why this is correct

    With unconstrained delegation, the computer can cache the TGT of any user who authenticates to it. If a domain administrator logs on, the attacker can extract that TGT and use it to impersonate the administrator across the domain. This directly enables the escalation described in the scenario.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.