Courseiva

CCNA Kerberos Attacks Questions

20 questions · Kerberos Attacks · All types, answers revealed

1
MCQmedium

During an internal assessment, a tester has valid domain credentials for a standard user and captures Kerberos traffic with Wireshark. The tester notices several TGS-REQ packets for service principal names ending in "/MSSQLSvc" across multiple hosts. The tester wants to identify which accounts are vulnerable to offline password cracking without triggering account lockouts. Which action should the tester take next?

A.Run BloodHound with the collection method All to map SPN relationships and infer which accounts use weak passwords.
B.Perform an AS-REP Roasting scan against all domain users to collect encrypted pre-authentication responses.
C.Use Rubeus with the kerberoast action to request TGS tickets for the MSSQLSvc SPNs and save the extracted hashes for offline cracking.
D.Attempt to authenticate to each MSSQLSvc SPN using the compromised user's credentials to confirm access.
AnswerC

Requesting TGS tickets for accounts with registered SPNs returns the service ticket encrypted with the target account's NTLM hash, which can be cracked offline without contacting the target service. Rubeus kerberoast automates this extraction and produces a hashcat-compatible format. The compromised user only needs a valid TGT, so no lockout risk is introduced against the service account.

Why this answer

Requesting service tickets for accounts with registered SPNs yields TGS material encrypted with the service account's key, enabling offline cracking without lockout risk. The captured TGS-REQ traffic for MSSQLSvc SPNs confirms kerberoastable targets. Tools like Rubeus automate extraction and output hashcat-compatible hashes, letting the tester verify weak service account passwords safely.

Exam trap

The trap here is confusing kerberoasting with interactive service authentication or AS-REP Roasting, when the observed TGS-REQ traffic points specifically to extracting TGS tickets for offline cracking.

2
Multi-Selectmedium

Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?

Select 2 answers
A.Multiple TGS-REQ packets from a single workstation targeting various SPNs within a short timeframe.
B.A sudden spike in AS-REQ events using expired Kerberos TGTs.
C.The use of RC4-HMAC encryption in service ticket requests for accounts that support AES.
D.Frequent failed logins followed by a successful Kerberos authentication.
E.An influx of TGT-REQ packets originating from non-domain controllers.
AnswersA, C

A high volume of TGS-REQ requests from a single source is a hallmark of Kerberoasting, as the attacker attempts to collect multiple tickets to maximize their chances of cracking service account passwords. This behavioral pattern is distinct from normal network activity where users typically request tickets incrementally.

Why this answer

Kerberoasting is characterized by the bulk request of service tickets and the subsequent offline cracking of the service account's password. Detectors look for anomalous TGS-REQ volume and specific encryption types (like RC4-HMAC) in the requests. Identifying these patterns allows security analysts to pinpoint service accounts that are currently under attack, enabling timely password resets or the implementation of Group Managed Service Accounts (gMSAs) to mitigate future risk.

Exam trap

Candidates often confuse Kerberoasting indicators with AS-REP roasting indicators, mistakenly looking for pre-authentication disabled flags instead of high-volume TGS-REQ packets and weak encryption types.

3
MCQmedium

Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?

A.The PAC is always encrypted with the user's password, making it easy to crack.
B.The PAC allows attackers to inject arbitrary group memberships into a forged ticket.
C.The PAC prevents the KDC from verifying the ticket's signature.
D.The PAC is required for TGT requests, making it a primary target for sniffers.
AnswerB

In a forgery scenario, the attacker controls the entire ticket construction, including the PAC. By modifying the PAC data, the attacker can grant themselves administrative group memberships, effectively becoming a domain administrator as far as any service accepting the ticket is concerned, regardless of their real identity.

Why this answer

The PAC is a data structure embedded within Kerberos tickets that contains user identity and group membership information. Because the PAC is signed by the KDC, it is normally trusted. However, if an attacker can forge a ticket, they can also manipulate the PAC within that ticket to elevate their privileges, such as adding themselves to the 'Domain Admins' group, bypassing normal authorization checks completely.

Exam trap

Test-takers frequently believe the PAC is verified directly by client machines or member servers without KDC validation, misunderstanding where authorization data is processed and trusted.

4
MCQmedium

A penetration tester has obtained a low-privileged domain user's cleartext credentials. During reconnaissance, the tester wants to enumerate which accounts in the domain are configured with Service Principal Names (SPNs) and are therefore candidates for Kerberoasting, without triggering a lockout or modifying the directory. Which of the following approaches best accomplishes this?

A.Perform an SMB null session against each domain controller and parse the SAM database for accounts ending in the $ suffix.
B.Run a targeted LDAP query for objects where servicePrincipalName is present and not null, using tools such as GetUserSPNs.py or PowerView's Get-DomainUser -SPN.
C.Send an AS-REQ for every account in the domain and inspect which accounts return a pre-authentication error versus a valid AS-REP.
D.Request a TGS for the krbtgt service and inspect the returned ticket's encryption type to infer which accounts have SPNs.
AnswerB

Querying the directory for objects with a non-null servicePrincipalName attribute returns exactly the accounts eligible for Kerberoasting. This read-only LDAP operation requires only standard authenticated access, does not modify the directory, and does not generate failed logon events that could cause lockouts, making it the correct enumeration technique in this scenario.

Why this answer

Kerberoasting requires identifying domain accounts that have a servicePrincipalName set, because those accounts can have a service ticket requested and cracked offline. The cleanest way to find them is a read-only LDAP search filtering on servicePrincipalName. This technique uses only legitimate authenticated access, avoids lockout risk, and does not alter the directory, making it the appropriate reconnaissance step.

Exam trap

The trap here is confusing AS-REP Roasting (accounts without pre-authentication) with Kerberoasting (accounts with SPNs), which are entirely different account configurations.

5
MCQmedium

During a penetration test, a tester compromises a workstation and extracts a Kerberos TGT for a domain user from memory. The tester wants to use this TGT to access a file share on a remote server without knowing the user's password. Which action should the tester take?

A.Perform an S4U2Self request to obtain a service ticket for the file share using the extracted TGT.
B.Forge a new TGT using the user's NTLM hash, which can be derived from the extracted TGT.
C.Crack the TGT offline to recover the user's password, then authenticate normally to the file share.
D.Inject the TGT into the current session using Rubeus ptt and request a service ticket for the file share's SPN.
AnswerD

Pass-the-ticket involves injecting a stolen TGT into a logon session so the system can request service tickets on behalf of the user. With the TGT injected, the tester can obtain a TGS for the file share's SPN and access it without the password. Rubeus ptt performs the injection, and the resulting TGS enables authenticated access.

Why this answer

Injecting a stolen TGT into the current session allows the system to request service tickets as the compromised user, enabling access to resources like file shares without the password. Pass-the-ticket leverages the TGT's validity until expiration, making it a powerful lateral movement technique.

Exam trap

The trap here is assuming a TGT can be cracked or used to derive the user's hash, when it must instead be injected into a session to request service tickets.

6
Multi-Selecthard

A penetration tester has compromised a workstation and obtained a Kerberos TGT for a low-privileged domain user. The tester wants to abuse unconstrained delegation configured on a member server named APP01 to escalate privileges. Which two actions are required to achieve this? (Choose two.)

Select 2 answers
A.Request a service ticket for the krbtgt account using the compromised user's TGT.
B.Extract the cached TGT from APP01 and inject it into the tester's session for reuse.
C.Disable Kerberos pre-authentication on the compromised user account to facilitate ticket capture.
D.Coerce a domain controller to authenticate to APP01 so its TGT is captured in memory.
E.Modify the msDS-AllowedToDelegateTo attribute on APP01 to include the domain controller.
AnswersB, D

Once the domain controller's TGT is cached on APP01, extracting it with a tool such as Rubeus or Mimikatz and injecting it into the tester's session allows the tester to impersonate the DC. Presenting that TGT yields a service ticket with domain controller privileges, enabling DCSync or other high-impact actions.

Why this answer

Abusing unconstrained delegation requires forcing a high-value account, such as a domain controller, to authenticate to the delegation-enabled host so its TGT is cached, then extracting and reusing that TGT. Coercion techniques place the DC's TGT on APP01, and extraction tools enable impersonation, leading to domain compromise.

Exam trap

The trap here is assuming the low-privileged user's own TGT is sufficient, when the attack depends on capturing a domain controller's TGT that is cached on the unconstrained delegation host.

7
Multi-Selectmedium

You are performing a Kerberoasting attack against a domain. After requesting service tickets for accounts with SPNs, you extract the tickets and attempt to crack them offline. Which two factors most directly determine the success of cracking these tickets? (Choose two.)

Select 2 answers
A.The number of service tickets requested
B.The domain functional level
C.The encryption type used for the service ticket
D.The physical location of the domain controller
E.The complexity and length of the service account's password
AnswersC, E

The encryption type (e.g., RC4_HMAC_MD5 or AES256_CTS_HMAC_SHA1_96) determines the speed and difficulty of cracking. RC4 tickets are encrypted with the service account's NTLM hash, which is faster to crack than AES tickets that use stronger key derivation. Therefore, the encryption type directly impacts the cracking success rate and time.

Why this answer

The success of cracking Kerberoasted tickets hinges on the encryption type and the service account's password strength. RC4 tickets are faster to crack than AES, and weak passwords are vulnerable to dictionary attacks. Other factors like number of tickets, domain functional level, or DC location do not affect the cryptographic difficulty of cracking.

Exam trap

The trap here is assuming that requesting more tickets or having a higher domain functional level improves cracking success, when actually only the encryption type and password strength matter.

8
MCQmedium

An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?

A.The NTLM hash is insufficient because it cannot be used to request a Ticket Granting Ticket (TGT).
B.The NTLM hash is only useful for Pass-the-Hash attacks and cannot facilitate any Kerberos interactions.
C.Kerberoasting targets the service account's password hash by requesting a TGS, not by leveraging existing NTLM hashes.
D.The NTLM hash must first be converted to a Kerberos AES-256 key before a TGS request can be initiated.
AnswerC

Kerberoasting relies on the KDC encrypting a service ticket with the target service account's password. The attacker requests this ticket and then attempts to brute-force the password offline. Possessing the NTLM hash of the account does not provide the encrypted TGS blob needed for this specific offline cracking methodology.

Why this answer

Kerberoasting requires requesting a Service Ticket (TGS) from the Key Distribution Center (KDC) for a specific Service Principal Name (SPN). The attacker then extracts the encrypted TGS blob from memory or network traffic to crack the service account's password offline. The NTLM hash is a separate credential format; having it allows for Pass-the-Hash or silver ticket creation, but does not involve the KDC-based SPN request process required for Kerberoasting.

Exam trap

Candidates often conflate NTLM hash usage (Pass-the-Hash) with Kerberoasting, failing to realize Kerberoasting requires a TGS ticket request from the KDC, not just an existing hash.

9
MCQmedium

What is the primary objective of a 'Kerberos Armoring' (FAST) implementation?

A.To prevent the domain controller from logging failed authentication attempts.
B.To protect the initial authentication exchange from interception and modification.
C.To force all service accounts to use AES-256 encryption for tickets.
D.To bypass the need for a TGT during service authentication.
AnswerB

FAST (Flexible Authentication Secure Tunneling) establishes a secure tunnel between the client and the KDC for the AS-REQ/AS-REP exchange. This prevents attackers from sniffing credentials or tampering with the initial ticket request process, hardening the domain against several common Kerberos-based attacks.

Why this answer

Kerberos Armoring, or Flexible Authentication Secure Tunneling (FAST), protects the exchange between the client and the KDC by creating a secure, encrypted tunnel using a separate key. This protects the AS-REQ and AS-REP packets from interception and tampering, effectively neutralizing attacks that rely on sniffing or modifying the initial authentication traffic.

Exam trap

Test-takers often assume Kerberos Armoring is designed to encrypt ticket-granting service sessions or hide group memberships, missing its focus on the initial AS exchange.

10
MCQeasy

What is the fundamental difference between Golden Ticket and Silver Ticket attacks?

A.Golden Tickets require communicating with the KDC, whereas Silver Tickets do not.
B.Golden Tickets target the domain controller, while Silver Tickets target user workstations.
C.Golden Tickets grant access to any service in the domain, while Silver Tickets only grant access to one service.
D.Silver Tickets are more powerful because they are harder to detect than Golden Tickets.
AnswerC

Golden Tickets are forged TGTs, acting as a master key for the domain. Silver Tickets are forged TGS tickets for a specific service. By using the service account's password hash, the attacker can only successfully authenticate to the service associated with that specific account.

Why this answer

The primary difference lies in the level of access and the secret used to forge the ticket. Golden Tickets use the KRBTGT hash to forge a TGT, granting access to any service in the domain. Silver Tickets use the service account hash to forge a TGS, granting access only to the specific service associated with that account.

Golden Tickets require a higher level of initial privilege to obtain the KRBTGT hash.

Exam trap

Candidates often confuse the scope of access, incorrectly assuming a Silver Ticket provides domain-wide admin access, whereas it is strictly limited to the specific service account's permissions.

11
MCQhard

During a penetration test, an operator compromises a workstation where a domain administrator has an active logon session. The operator wants to extract the domain administrator's Kerberos TGT from LSASS and reuse it to access other systems without knowing the administrator's password. Which of the following techniques is specifically designed for this purpose?

A.Kerberoasting by requesting service tickets for SPNs associated with the domain administrator account.
B.Silver Ticket creation by forging a service ticket with the domain administrator's NTLM hash.
C.Pass-the-Ticket using tools such as Mimikatz's sekurlsa::tickets /export and kerberos::ptt.
D.Overpass-the-Hash using Mimikatz's sekurlsa::pth with the administrator's NTLM hash.
AnswerC

Pass-the-Ticket extracts a valid Kerberos ticket (including a TGT) from LSASS using sekurlsa::tickets and injects it into the current logon session with kerberos::ptt. This allows the operator to authenticate as the administrator to other services without the password or hash, directly satisfying the scenario's requirement of reusing the captured TGT.

Why this answer

Pass-the-Ticket is the technique that extracts and reuses a Kerberos ticket from a compromised host. When a domain administrator has an active session, their TGT resides in LSASS and can be exported and injected into another session. This grants the operator the administrator's access without needing the password or hash, perfectly matching the scenario's constraints.

Exam trap

The trap here is assuming that any Kerberos attack requires the account's password or hash; Pass-the-Ticket instead reuses a ticket already present in memory.

12
MCQhard

What is the primary risk associated with 'Unconstrained Delegation' in Active Directory?

A.It forces the use of NTLM for all authentication requests.
B.It allows the service to cache user TGTs, which can be extracted by an attacker.
C.It requires the domain controller to store plaintext passwords for all users.
D.It prevents the KDC from enforcing password expiration policies.
AnswerB

Unconstrained delegation causes the KDC to send the user's TGT to the service along with the TGS. The service caches this TGT in memory. An attacker with administrative access to that machine can dump the memory, retrieve the TGT, and use it to impersonate users anywhere.

Why this answer

In unconstrained delegation, a service account can take a user's TGT (which is sent to the service during authentication) and store it in its own memory. An attacker who compromises such a service can extract these stored TGTs. Because the TGT is valid for the whole domain, the attacker can then impersonate those users to any service in the domain, leading to total environment compromise.

Exam trap

Candidates often confuse Unconstrained Delegation with Constrained Delegation. They incorrectly assume it involves the KDC directly or limits the service to specific target servers, missing the core risk of TGT caching.

13
MCQeasy

A penetration tester is analyzing a Kerberos attack that involved forging a ticket to gain access to a specific server. The ticket was encrypted with the server's machine account hash and did not involve communication with the domain controller. Which type of attack does this describe?

A.Silver Ticket
B.Golden Ticket
C.AS-REP Roasting
D.Kerberoasting
AnswerA

A Silver Ticket is a forged service ticket (TGS) encrypted with the target service account's hash, such as a machine account hash for a server. It does not require communication with the domain controller because the service decrypts the ticket with its own key and trusts the embedded PAC. This matches the description of gaining access to a specific server without DC interaction.

Why this answer

A Silver Ticket is a forged service ticket encrypted with the target service's key, allowing access without contacting the DC. Golden Tickets are forged TGTs encrypted with the krbtgt hash. Kerberoasting and AS-REP Roasting involve requesting legitimate tickets for offline cracking, not forging.

Thus, the description matches a Silver Ticket.

Exam trap

The trap here is confusing Silver Tickets with Golden Tickets; both are forged, but Silver Tickets target a specific service and use the service's key, while Golden Tickets target the domain and use the krbtgt key.

14
MCQmedium

During an internal penetration test, you have obtained cleartext credentials for a low-privileged Active Directory user. You want to enumerate which user accounts do not require Kerberos preauthentication so you can request AS-REP messages and crack them offline. Which Impacket tool and command should you use?

A.ticketer.py -nthash <hash> -domain domain.local -dc-ip 10.0.0.1 user
B.GetNPUsers.py -request -dc-ip 10.0.0.1 domain/user:password
C.GetUserSPNs.py -request -dc-ip 10.0.0.1 domain/user:password
D.secretsdump.py domain/user:password@10.0.0.1
AnswerB

GetNPUsers.py is the Impacket tool specifically built for AS-REP Roasting. With the -request flag, it queries Active Directory for accounts where the 'Do not require Kerberos preauthentication' flag is set, then sends an AS-REQ for each and captures the returned AS-REP, which is encrypted with the user's password hash. This aligns exactly with your goal of enumerating and extracting crackable AS-REP messages.

Why this answer

AS-REP Roasting targets accounts that have Kerberos preauthentication disabled. The Impacket script GetNPUsers.py with the -request flag queries the domain for such accounts and requests an AS-REP for each, which can then be cracked offline. The other tools serve different purposes: GetUserSPNs.py is for Kerberoasting, secretsdump.py extracts secrets from hosts, and ticketer.py forges tickets.

Exam trap

The trap here is confusing AS-REP Roasting with Kerberoasting; both involve requesting encrypted tickets for offline cracking, but they target different account configurations and use different Impacket scripts.

15
Multi-Selectmedium

A penetration tester is reviewing Active Directory for Kerberos delegation misconfigurations that could allow privilege escalation. Which of the following TWO configurations should the tester flag as directly enabling an attacker to impersonate a domain administrator to a target service? (Choose two.)

Select 2 answers
A.A standard user account with the 'Account is sensitive and cannot be delegated' flag set.
B.A user account configured for constrained delegation with the 'Use any authentication protocol' option and msDS-AllowedToDelegateTo set to a sensitive service.
C.A group Managed Service Account (gMSA) with a 120-character automatically rotated password.
D.A domain controller configured with the 'Trusted for Delegation' flag but no users currently logged on.
E.A computer account configured for unconstrained delegation where a domain administrator has authenticated.
AnswersB, E

Constrained delegation with protocol transition allows the service to obtain a forwardable ticket to any listed service on behalf of any user, without that user authenticating. If the allowed service is sensitive, an attacker controlling the account can impersonate a domain administrator to that service, achieving escalation.

Why this answer

Unconstrained delegation caches TGTs of authenticating users, so a domain administrator's logon on such a host exposes their TGT for impersonation. Constrained delegation with protocol transition and a sensitive target allows an attacker controlling the delegating account to impersonate any user, including administrators, to that service. Both configurations directly enable the described escalation and should be flagged.

Exam trap

The trap here is treating any delegation flag as exploitable, when only specific combinations like unconstrained delegation with a privileged logon or constrained delegation with protocol transition to a sensitive service actually enable impersonation.

16
MCQmedium

What is the primary security benefit of implementing Group Managed Service Accounts (gMSAs) in an environment vulnerable to Kerberoasting?

A.gMSAs prevent the KDC from issuing service tickets for the account.
B.gMSAs require multi-factor authentication for every TGS-REQ performed.
C.gMSAs use long, complex passwords that are automatically rotated by the domain controller.
D.gMSAs force all Kerberos traffic to be encrypted using AES-256 only.
AnswerC

The core security advantage of gMSAs is the management of long, high-entropy passwords that are rotated automatically. By removing the need for manual password management, gMSAs eliminate the risk of weak, static passwords that are easily brute-forced offline after a Kerberoasting ticket capture.

Why this answer

gMSAs are designed to mitigate the risks associated with long-term static service account passwords. They feature automatically managed, complex passwords that are rotated frequently by the Active Directory domain controller. Because the passwords are long and changed regularly, they are effectively impossible to crack offline even if an attacker successfully captures the encrypted TGS ticket during a Kerberoasting attempt, rendering the attack functionally useless.

Exam trap

Students often believe gMSAs are meant to prevent all Active Directory attacks, overlooking that their specific security benefit is the automatic rotation of complex passwords to defeat offline cracking.

17
MCQeasy

A penetration tester is reviewing Kerberos traffic and notices that a user account has the DONT_REQ_PREAUTH flag set in its userAccountControl attribute. The tester wants to obtain crackable material for this account without any domain credentials. Which technique should the tester use?

A.Golden ticket creation by forging a TGT using the krbtgt hash obtained from the domain controller.
B.Kerberoasting by requesting a TGS for an SPN associated with the account and cracking the service ticket.
C.Silver ticket creation by forging a service ticket using the target account's NTLM hash.
D.AS-REP Roasting by sending an AS-REQ without pre-authentication and capturing the encrypted AS-REP.
AnswerD

When pre-authentication is disabled, the KDC returns an AS-REP containing data encrypted with the user's password-derived key without requiring the requester to prove knowledge of the password. An unauthenticated attacker can request this and crack the encrypted portion offline. This directly exploits the DONT_REQ_PREAUTH flag and requires no domain credentials.

Why this answer

The DONT_REQ_PREAUTH flag allows an unauthenticated attacker to request an AS-REP for the account and receive data encrypted with the user's key. Capturing that response enables offline password cracking without any domain credentials, directly exploiting the disabled pre-authentication setting.

Exam trap

The trap here is conflating AS-REP Roasting with Kerberoasting, when the absence of pre-authentication and lack of credentials point specifically to requesting an AS-REP for offline cracking.

18
MCQhard

You have compromised a workstation and extracted the NTLM hash of a service account that is configured for unconstrained delegation. You want to craft a Silver Ticket to impersonate a domain administrator when accessing a specific file server. Which piece of information is absolutely required to forge this ticket?

A.The domain SID and the target user's RID
B.A valid TGT for the service account
C.The service account's NTLM hash or Kerberos key
D.The krbtgt account's NTLM hash
AnswerC

A Silver Ticket is a forged service ticket (TGS) encrypted with the target service account's key. To create it, you need the NTLM hash or Kerberos key (AES) of the account under which the service runs. In this scenario, you have the service account's NTLM hash, which is exactly what is needed to encrypt the ticket and have it accepted by the file server without contacting the KDC.

Why this answer

To forge a Silver Ticket, the attacker must have the target service account's NTLM hash or Kerberos key to encrypt the service ticket. The domain SID and user RID are needed for the PAC but are not the encryption key. A TGT is not required because the ticket is presented directly to the service.

The krbtgt hash is for Golden Tickets.

Exam trap

The trap here is mixing up the key material needed for a Silver Ticket versus a Golden Ticket; the Silver Ticket uses the service account's key, not the krbtgt key.

19
MCQmedium

Which of the following describes the 'AS-REP Roasting' attack?

A.It targets service accounts that are configured with SPNs.
B.It relies on the interception of a TGS request to obtain encrypted credentials.
C.It allows an attacker to crack user account passwords for accounts without pre-authentication.
D.It is a technique for escalating privileges using the KRBTGT account.
AnswerC

When pre-authentication is disabled, the KDC will provide an AS-REP ticket to anyone who asks. This ticket is encrypted with the user's password. The attacker can capture this response and perform an offline brute-force attack to recover the original password.

Why this answer

AS-REP Roasting targets user accounts that have 'Do not require Kerberos preauthentication' enabled. An attacker can request a TGT for such an account without providing a password. The KDC responds with an encrypted ticket (the AS-REP) that the attacker can then extract and crack offline, similar to how Kerberoasting works, to obtain the user's plaintext password.

Exam trap

Many candidates confuse AS-REP Roasting with Kerberoasting. They incorrectly believe it involves requesting service tickets from the KDC, failing to realize it specifically targets accounts where pre-authentication is disabled.

20
MCQmedium

Which Kerberos feature is specifically exploited when an attacker uses 'constrained delegation' to escalate privileges?

A.The TGT's ability to be renewed indefinitely.
B.The S4U2Self and S4U2Proxy extensions.
C.The PAC validation performed by the Domain Controller.
D.The ability to use RC4 encryption for TGS requests.
AnswerB

S4U2Self allows a service to get a ticket for itself on behalf of a user, and S4U2Proxy allows the service to request a ticket to a second service on behalf of that user. These extensions are the technical foundation for constrained delegation in Active Directory.

Why this answer

Constrained delegation allows a service to impersonate a user to a specific set of other services, defined in the 'msDS-AllowedToDelegateTo' attribute. If an attacker compromises a service account configured for constrained delegation, they can request a service ticket for any user to the allowed target services. This allows the attacker to pivot throughout the network while impersonating high-privilege users without needing their credentials.

Exam trap

Candidates frequently select unconstrained delegation extensions or standard ticket-granting ticket options, confusing the specific S4U mechanisms used in constrained delegation attacks.

Ready to test yourself?

Try a timed practice session using only Kerberos Attacks questions.