Courseiva

GPEN · domain

Kerberos Attacks

This domain covers abusing Kerberos authentication in Windows Active Directory: pre-auth weaknesses, ticket forgery, delegation misconfigurations, and service account cracking. GPEN questions present traffic captures, extracted hashes, or account attributes and require you to select the correct attack, tool, or defensive control rather than recall theory alone.

20 questions3 easy13 medium4 hard

Focused practice

Practice Kerberos Attacks questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Kerberos Attacks

You must map an observed Kerberos condition to the correct attack: AS-REP roasting, Kerberoasting, Silver/Golden Ticket, or delegation abuse. The critical skill is distinguishing which ticket type and hash source each scenario implies before choosing a tool or command.

Identifying AS-REP roasting when DONT_REQ_PREAUTH is set and extracting crackable hashes with GetNPUsers or Rubeus.

Forging Silver and Golden Tickets using service or krbtgt NTLM hashes, including PAC and SID manipulation.

Exploiting unconstrained, constrained, and resource-based constrained delegation via S4U2Self and S4U2Proxy.

Kerberoasting service accounts with SPNs using GetUserSPNs or Rubeus and cracking with Hashcat mode 13100.

Watch out for

Common Kerberos Attacks exam traps

  • ▸Confusing AS-REP roasting (no pre-auth required) with Kerberoasting (requires SPN and TGS request), leading to wrong tool selection.
  • ▸Assuming a Silver Ticket grants domain-wide access; it is scoped to the targeted service and its host, not the whole domain.
  • ▸Forgetting that gMSAs rotate passwords automatically, so Kerberoasting yields no crackable material for those accounts.

Question index

All Kerberos Attacks questions (20)

Click any question to see the full explanation, or start a practice session above.

1

During an internal assessment, a tester has valid domain credentials for a standard user and captures Kerberos traffic with Wireshark. The tester notices several TGS-REQ packets for service principal names ending in "/MSSQLSvc" across multiple hosts. The tester wants to identify which accounts are vulnerable to offline password cracking without triggering account lockouts. Which action should the tester take next?

Medium
2

Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?

Medium
3

Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?

Medium
4

A penetration tester has obtained a low-privileged domain user's cleartext credentials. During reconnaissance, the tester wants to enumerate which accounts in the domain are configured with Service Principal Names (SPNs) and are therefore candidates for Kerberoasting, without triggering a lockout or modifying the directory. Which of the following approaches best accomplishes this?

Medium
5

During a penetration test, a tester compromises a workstation and extracts a Kerberos TGT for a domain user from memory. The tester wants to use this TGT to access a file share on a remote server without knowing the user's password. Which action should the tester take?

Medium
6

A penetration tester has compromised a workstation and obtained a Kerberos TGT for a low-privileged domain user. The tester wants to abuse unconstrained delegation configured on a member server named APP01 to escalate privileges. Which two actions are required to achieve this? (Choose two.)

Hard
7

You are performing a Kerberoasting attack against a domain. After requesting service tickets for accounts with SPNs, you extract the tickets and attempt to crack them offline. Which two factors most directly determine the success of cracking these tickets? (Choose two.)

Medium
8

An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?

Medium
9

What is the primary objective of a 'Kerberos Armoring' (FAST) implementation?

Medium
10

What is the fundamental difference between Golden Ticket and Silver Ticket attacks?

Easy
11

During a penetration test, an operator compromises a workstation where a domain administrator has an active logon session. The operator wants to extract the domain administrator's Kerberos TGT from LSASS and reuse it to access other systems without knowing the administrator's password. Which of the following techniques is specifically designed for this purpose?

Hard
12

What is the primary risk associated with 'Unconstrained Delegation' in Active Directory?

Hard
13

A penetration tester is analyzing a Kerberos attack that involved forging a ticket to gain access to a specific server. The ticket was encrypted with the server's machine account hash and did not involve communication with the domain controller. Which type of attack does this describe?

Easy
14

During an internal penetration test, you have obtained cleartext credentials for a low-privileged Active Directory user. You want to enumerate which user accounts do not require Kerberos preauthentication so you can request AS-REP messages and crack them offline. Which Impacket tool and command should you use?

Medium
15

A penetration tester is reviewing Active Directory for Kerberos delegation misconfigurations that could allow privilege escalation. Which of the following TWO configurations should the tester flag as directly enabling an attacker to impersonate a domain administrator to a target service? (Choose two.)

Medium
16

What is the primary security benefit of implementing Group Managed Service Accounts (gMSAs) in an environment vulnerable to Kerberoasting?

Medium
17

A penetration tester is reviewing Kerberos traffic and notices that a user account has the DONT_REQ_PREAUTH flag set in its userAccountControl attribute. The tester wants to obtain crackable material for this account without any domain credentials. Which technique should the tester use?

Easy
18

You have compromised a workstation and extracted the NTLM hash of a service account that is configured for unconstrained delegation. You want to craft a Silver Ticket to impersonate a domain administrator when accessing a specific file server. Which piece of information is absolutely required to forge this ticket?

Hard
19

Which of the following describes the 'AS-REP Roasting' attack?

Medium
20

Which Kerberos feature is specifically exploited when an attacker uses 'constrained delegation' to escalate privileges?

Medium

Frequently asked questions

What does the Kerberos Attacks domain cover on the GPEN exam?
You must map an observed Kerberos condition to the correct attack: AS-REP roasting, Kerberoasting, Silver/Golden Ticket, or delegation abuse. The critical skill is distinguishing which ticket type and hash source each scenario implies before choosing a tool or command.
How many questions are in this domain?
This page lists all 20 Kerberos Attacks questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Kerberos Attacks questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN kerberos attacks Practice Questions