Courseiva
Advanced Password Attacks →mediumMultiple Choice

GPEN Advanced Password Attacks Practice Question

During an internal penetration test, an attacker intercepts an Active Directory Kerberos AS-REQ for a user account that does not have Kerberos pre-authentication enabled. What is the most effective post-exploitation technique for the operator to perform offline credential cracking against this captured artifact?

⚠ Common exam trap

Candidates often suggest performing a brute-force attack against the DC. This is incorrect because AS-REP Roasting allows the operator to perform the cracking offline, avoiding any interaction with the DC's lockout policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct an AS-REP roasting attack to extract the encrypted ticket portion and crack the underlying user password offline.

Disabling Kerberos pre-authentication allows an attacker to request an AS-REP for any targeted user account without knowing their password. The returned ticket contains a portion encrypted with the user's NTLM hash, which can then be attacked offline using hashcat or John the Ripper to recover the plaintext password. This attack vector bypasses standard lockout policies completely since no actual authentication attempts are made against the Domain Controller during the cracking phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Execute a DCSync attack using volume shadow copies to extract the NTDS.dit database directly from the primary domain controller.

    Why it's wrong here

    DCSync requires administrative privileges such as Replication Rights within the domain to impersonate a domain controller and request password data. This technique is entirely different from abusing missing pre-authentication settings on standard user accounts during an initial access phase.

  • ✗

    Perform a Kerberoasting attack to harvest service ticket hashes for accounts with registered Service Principal Names.

    Why it's wrong here

    Kerberoasting targets Service Principal Names by requesting TGS tickets for application services rather than requesting authentication blobs from accounts with pre-authentication explicitly disabled. These are fundamentally distinct ticket abuse mechanisms within the Kerberos protocol framework.

  • ✓

    Conduct an AS-REP roasting attack to extract the encrypted ticket portion and crack the underlying user password offline.

    Why this is correct

    Accounts configured without Kerberos pre-authentication allow anonymous request handling where the Key Distribution Center responds with an AS-REP ticket containing data encrypted with the user's password hash. Attackers capture this response and utilize GPU acceleration to perform offline dictionary attacks successfully.

  • ✗

    Inject a malicious golden ticket into memory after dumping the krbtgt account credentials from the lsass process.

    Why it's wrong here

    Golden ticket creation requires prior compromise of the krbtgt account master key to forge valid Ticket Granting Tickets. This attack assumes domain administrative control has already been achieved, whereas AS-REP roasting focuses on exploiting misconfigured domain user objects.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.