GPEN Attacking Password Hashes Practice Question
During a penetration test, a tester obtains a Kerberos TGS ticket for a service account and wants to crack it offline. The ticket is encrypted with RC4-HMAC. Which of the following best describes the primary reason this attack, known as Kerberoasting, is effective?
⚠ Common exam trap
Many candidates confuse Kerberoasting with Golden Ticket attacks, where the former targets service account TGS tickets encrypted with the service account's hash, while the latter forges TGTs using the KRBTGT hash.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The TGS ticket is encrypted with the service account's NT hash, which can be cracked offline without contacting the domain controller.
Kerberoasting works by requesting a TGS ticket for a service account with a registered SPN. The ticket is encrypted with the service account's NT hash, and because RC4-HMAC uses the NT hash directly as the encryption key, an attacker can extract the ticket and crack it offline. This avoids detection and does not require further domain controller interaction. The other options misidentify the encryption key or the attack's goal, such as forging golden tickets or extracting plaintext passwords, which are not part of Kerberoasting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The TGS ticket contains the service account's plaintext password, which can be read directly from the ticket.
Why it's wrong here
Kerberos tickets do not contain plaintext passwords; they are encrypted with a key derived from the password. The TGS ticket is encrypted with the service account's NT hash, and the goal is to crack that encryption to recover the password. Reading the ticket directly would not reveal the password. This option misrepresents the nature of Kerberos encryption and the Kerberoasting attack, which relies on offline cracking, not direct extraction.
- ✗
The TGS ticket is encrypted with the KRBTGT account's hash, allowing the attacker to forge golden tickets.
Why it's wrong here
The KRBTGT account hash is used to encrypt TGTs, not TGS tickets. Kerberoasting targets TGS tickets encrypted with the service account's hash. Forging golden tickets requires the KRBTGT hash, which is a different attack (Golden Ticket). The scenario is about cracking a TGS ticket for a service account, not about forging TGTs. Confusing these two concepts would lead to an incorrect understanding of the attack.
- ✓
The TGS ticket is encrypted with the service account's NT hash, which can be cracked offline without contacting the domain controller.
Why this is correct
Kerberoasting is effective because the TGS ticket is encrypted with the service account's NT hash (for RC4-HMAC). An attacker who requests a service ticket can extract it and attempt to crack the encryption offline, without further interaction with the domain controller. This allows stealthy password recovery. The scenario specifies RC4-HMAC encryption, which is particularly vulnerable because it uses the NT hash directly as the key, making it a prime target for offline cracking.
- ✗
The TGS ticket is signed with the domain's private key, which can be cracked to reveal the domain administrator's password.
Why it's wrong here
Kerberos tickets are not signed with a domain private key in the context of Kerberoasting. The domain's private key is not used to sign TGS tickets; instead, tickets are encrypted with symmetric keys derived from account passwords. The domain administrator's password is not directly recoverable from a service ticket. This option conflates asymmetric cryptography with the symmetric encryption used in Kerberos, leading to a misunderstanding of the attack's mechanics.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.