Courseiva
Kerberos Attacks →mediumMultiple Choice

GPEN Kerberos Attacks Practice Question

An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?

⚠ Common exam trap

Candidates often conflate NTLM hash usage (Pass-the-Hash) with Kerberoasting, failing to realize Kerberoasting requires a TGS ticket request from the KDC, not just an existing hash.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kerberoasting targets the service account's password hash by requesting a TGS, not by leveraging existing NTLM hashes.

Kerberoasting requires requesting a Service Ticket (TGS) from the Key Distribution Center (KDC) for a specific Service Principal Name (SPN). The attacker then extracts the encrypted TGS blob from memory or network traffic to crack the service account's password offline. The NTLM hash is a separate credential format; having it allows for Pass-the-Hash or silver ticket creation, but does not involve the KDC-based SPN request process required for Kerberoasting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The NTLM hash is insufficient because it cannot be used to request a Ticket Granting Ticket (TGT).

    Why it's wrong here

    Requesting a TGT requires an initial authentication exchange, such as AS-REQ, which typically uses the user's password or AES keys. While an NTLM hash can be used for NTLM authentication, it does not bypass the Kerberos protocol requirements for obtaining a TGS via an SPN request.

  • ✗

    The NTLM hash is only useful for Pass-the-Hash attacks and cannot facilitate any Kerberos interactions.

    Why it's wrong here

    The NTLM hash is indeed central to Pass-the-Hash, but it is not entirely useless for Kerberos. In mixed environments, NTLM hashes can sometimes be used to facilitate downgrade attacks or service authentication, but they remain fundamentally incompatible with the specific TGS-REQ/TGS-REP flow used for Kerberoasting.

  • ✓

    Kerberoasting targets the service account's password hash by requesting a TGS, not by leveraging existing NTLM hashes.

    Why this is correct

    Kerberoasting relies on the KDC encrypting a service ticket with the target service account's password. The attacker requests this ticket and then attempts to brute-force the password offline. Possessing the NTLM hash of the account does not provide the encrypted TGS blob needed for this specific offline cracking methodology.

  • ✗

    The NTLM hash must first be converted to a Kerberos AES-256 key before a TGS request can be initiated.

    Why it's wrong here

    There is no direct mathematical conversion from an NTLM hash to a Kerberos AES-256 key because they utilize different cryptographic primitives. NTLM uses MD4, while Kerberos uses HMAC-SHA1 or HMAC-SHA256. Attempting to convert them will not enable the Kerberoasting process as described in standard penetration testing workflows.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.