GPEN Advanced Password Attacks Practice Question
During an internal penetration test, an attacker intercepts an Active Directory Kerberos AS-REQ for a user account that does not have Kerberos pre-authentication enabled. What is the most effective post-exploitation technique for the operator to perform offline credential cracking against this captured artifact?
⚠ Common exam trap
Candidates often suggest performing a brute-force attack against the DC. This is incorrect because AS-REP Roasting allows the operator to perform the cracking offline, avoiding any interaction with the DC's lockout policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct an AS-REP roasting attack to extract the encrypted ticket portion and crack the underlying user password offline.
Disabling Kerberos pre-authentication allows an attacker to request an AS-REP for any targeted user account without knowing their password. The returned ticket contains a portion encrypted with the user's NTLM hash, which can then be attacked offline using hashcat or John the Ripper to recover the plaintext password. This attack vector bypasses standard lockout policies completely since no actual authentication attempts are made against the Domain Controller during the cracking phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Execute a DCSync attack using volume shadow copies to extract the NTDS.dit database directly from the primary domain controller.
Why it's wrong here
DCSync requires administrative privileges such as Replication Rights within the domain to impersonate a domain controller and request password data. This technique is entirely different from abusing missing pre-authentication settings on standard user accounts during an initial access phase.
- ✗
Perform a Kerberoasting attack to harvest service ticket hashes for accounts with registered Service Principal Names.
Why it's wrong here
Kerberoasting targets Service Principal Names by requesting TGS tickets for application services rather than requesting authentication blobs from accounts with pre-authentication explicitly disabled. These are fundamentally distinct ticket abuse mechanisms within the Kerberos protocol framework.
- ✓
Conduct an AS-REP roasting attack to extract the encrypted ticket portion and crack the underlying user password offline.
Why this is correct
Accounts configured without Kerberos pre-authentication allow anonymous request handling where the Key Distribution Center responds with an AS-REP ticket containing data encrypted with the user's password hash. Attackers capture this response and utilize GPU acceleration to perform offline dictionary attacks successfully.
- ✗
Inject a malicious golden ticket into memory after dumping the krbtgt account credentials from the lsass process.
Why it's wrong here
Golden ticket creation requires prior compromise of the krbtgt account master key to forge valid Ticket Granting Tickets. This attack assumes domain administrative control has already been achieved, whereas AS-REP roasting focuses on exploiting misconfigured domain user objects.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.