GPEN · domain
Kerberos Attacks
This domain covers abusing Kerberos authentication in Windows Active Directory: pre-auth weaknesses, ticket forgery, delegation misconfigurations, and service account cracking. GPEN questions present traffic captures, extracted hashes, or account attributes and require you to select the correct attack, tool, or defensive control rather than recall theory alone.
Focused practice
Practice Kerberos Attacks questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Kerberos Attacks
You must map an observed Kerberos condition to the correct attack: AS-REP roasting, Kerberoasting, Silver/Golden Ticket, or delegation abuse. The critical skill is distinguishing which ticket type and hash source each scenario implies before choosing a tool or command.
Identifying AS-REP roasting when DONT_REQ_PREAUTH is set and extracting crackable hashes with GetNPUsers or Rubeus.
Forging Silver and Golden Tickets using service or krbtgt NTLM hashes, including PAC and SID manipulation.
Exploiting unconstrained, constrained, and resource-based constrained delegation via S4U2Self and S4U2Proxy.
Kerberoasting service accounts with SPNs using GetUserSPNs or Rubeus and cracking with Hashcat mode 13100.
Watch out for
Common Kerberos Attacks exam traps
- ▸Confusing AS-REP roasting (no pre-auth required) with Kerberoasting (requires SPN and TGS request), leading to wrong tool selection.
- ▸Assuming a Silver Ticket grants domain-wide access; it is scoped to the targeted service and its host, not the whole domain.
- ▸Forgetting that gMSAs rotate passwords automatically, so Kerberoasting yields no crackable material for those accounts.
Question index
All Kerberos Attacks questions (20)
Click any question to see the full explanation, or start a practice session above.
During an internal assessment, a tester has valid domain credentials for a standard user and captures Kerberos traffic with Wireshark. The tester notices several TGS-REQ packets for service principal names ending in "/MSSQLSvc" across multiple hosts. The tester wants to identify which accounts are vulnerable to offline password cracking without triggering account lockouts. Which action should the tester take next?
Medium2Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?
Medium3Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?
Medium4A penetration tester has obtained a low-privileged domain user's cleartext credentials. During reconnaissance, the tester wants to enumerate which accounts in the domain are configured with Service Principal Names (SPNs) and are therefore candidates for Kerberoasting, without triggering a lockout or modifying the directory. Which of the following approaches best accomplishes this?
Medium5During a penetration test, a tester compromises a workstation and extracts a Kerberos TGT for a domain user from memory. The tester wants to use this TGT to access a file share on a remote server without knowing the user's password. Which action should the tester take?
Medium6A penetration tester has compromised a workstation and obtained a Kerberos TGT for a low-privileged domain user. The tester wants to abuse unconstrained delegation configured on a member server named APP01 to escalate privileges. Which two actions are required to achieve this? (Choose two.)
Hard7You are performing a Kerberoasting attack against a domain. After requesting service tickets for accounts with SPNs, you extract the tickets and attempt to crack them offline. Which two factors most directly determine the success of cracking these tickets? (Choose two.)
Medium8An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?
Medium9What is the primary objective of a 'Kerberos Armoring' (FAST) implementation?
Medium10What is the fundamental difference between Golden Ticket and Silver Ticket attacks?
Easy11During a penetration test, an operator compromises a workstation where a domain administrator has an active logon session. The operator wants to extract the domain administrator's Kerberos TGT from LSASS and reuse it to access other systems without knowing the administrator's password. Which of the following techniques is specifically designed for this purpose?
Hard12What is the primary risk associated with 'Unconstrained Delegation' in Active Directory?
Hard13A penetration tester is analyzing a Kerberos attack that involved forging a ticket to gain access to a specific server. The ticket was encrypted with the server's machine account hash and did not involve communication with the domain controller. Which type of attack does this describe?
Easy14During an internal penetration test, you have obtained cleartext credentials for a low-privileged Active Directory user. You want to enumerate which user accounts do not require Kerberos preauthentication so you can request AS-REP messages and crack them offline. Which Impacket tool and command should you use?
Medium15A penetration tester is reviewing Active Directory for Kerberos delegation misconfigurations that could allow privilege escalation. Which of the following TWO configurations should the tester flag as directly enabling an attacker to impersonate a domain administrator to a target service? (Choose two.)
Medium16What is the primary security benefit of implementing Group Managed Service Accounts (gMSAs) in an environment vulnerable to Kerberoasting?
Medium17A penetration tester is reviewing Kerberos traffic and notices that a user account has the DONT_REQ_PREAUTH flag set in its userAccountControl attribute. The tester wants to obtain crackable material for this account without any domain credentials. Which technique should the tester use?
Easy18You have compromised a workstation and extracted the NTLM hash of a service account that is configured for unconstrained delegation. You want to craft a Silver Ticket to impersonate a domain administrator when accessing a specific file server. Which piece of information is absolutely required to forge this ticket?
Hard19Which of the following describes the 'AS-REP Roasting' attack?
Medium20Which Kerberos feature is specifically exploited when an attacker uses 'constrained delegation' to escalate privileges?
MediumOther domains
All GPEN exam domains
Frequently asked questions
- What does the Kerberos Attacks domain cover on the GPEN exam?
- You must map an observed Kerberos condition to the correct attack: AS-REP roasting, Kerberoasting, Silver/Golden Ticket, or delegation abuse. The critical skill is distinguishing which ticket type and hash source each scenario implies before choosing a tool or command.
- How many questions are in this domain?
- This page lists all 20 Kerberos Attacks questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Kerberos Attacks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.