Courseiva
Kerberos Attacks →easyMultiple Choice

GPEN Kerberos Attacks Practice Question

A penetration tester is reviewing Kerberos traffic and notices that a user account has the DONT_REQ_PREAUTH flag set in its userAccountControl attribute. The tester wants to obtain crackable material for this account without any domain credentials. Which technique should the tester use?

⚠ Common exam trap

The trap here is conflating AS-REP Roasting with Kerberoasting, when the absence of pre-authentication and lack of credentials point specifically to requesting an AS-REP for offline cracking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AS-REP Roasting by sending an AS-REQ without pre-authentication and capturing the encrypted AS-REP.

The DONT_REQ_PREAUTH flag allows an unauthenticated attacker to request an AS-REP for the account and receive data encrypted with the user's key. Capturing that response enables offline password cracking without any domain credentials, directly exploiting the disabled pre-authentication setting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Golden ticket creation by forging a TGT using the krbtgt hash obtained from the domain controller.

    Why it's wrong here

    Forging a golden ticket requires the krbtgt account's NTLM hash, which is not available without prior domain compromise. The scenario provides no credentials and focuses on a single user's pre-authentication setting. Golden tickets are a persistence mechanism, not a method to obtain crackable material for one account.

  • ✗

    Kerberoasting by requesting a TGS for an SPN associated with the account and cracking the service ticket.

    Why it's wrong here

    Kerberoasting requires the target account to have a registered SPN and the attacker to hold a valid TGT for any domain user. The scenario specifies no domain credentials and highlights a pre-authentication flag, not an SPN. Thus Kerberoasting is not applicable to this specific account configuration.

  • ✗

    Silver ticket creation by forging a service ticket using the target account's NTLM hash.

    Why it's wrong here

    Creating a silver ticket requires possessing the target service account's NTLM hash, which the tester does not have. The DONT_REQ_PREAUTH flag indicates an AS-REP Roasting opportunity, not a service ticket forgery path. This technique would not yield crackable material from the account.

  • ✓

    AS-REP Roasting by sending an AS-REQ without pre-authentication and capturing the encrypted AS-REP.

    Why this is correct

    When pre-authentication is disabled, the KDC returns an AS-REP containing data encrypted with the user's password-derived key without requiring the requester to prove knowledge of the password. An unauthenticated attacker can request this and crack the encrypted portion offline. This directly exploits the DONT_REQ_PREAUTH flag and requires no domain credentials.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.