GPEN Advanced Password Attacks Practice Question
During an internal penetration test, an operator intercepts an AS-REP response for a user account that does not have Kerberos pre-authentication enabled. What is the most efficient next step to recover the account password offline?
⚠ Common exam trap
Candidates often confuse AS-REP roasting with Kerberoasting, assuming a valid domain user account is required to request the ticket when AS-REP roasting explicitly targets accounts lacking pre-authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use GetNPUsers.py to request the AS-REP ticket and crack the derived hash offline using Hashcat mode 18200.
Disabling Kerberos pre-authentication allows any unauthenticated user to request an AS-REP for that account, containing a ticket encrypted with the user's secret key. Tools like Rubeus or GetNPUsers.py can harvest these tickets, which are formatted specifically for offline cracking using hashcat mode 18200 without requiring valid domain credentials initially.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run GetUserSPNs.py to request service ticket hashes for Kerberoasting against the domain controller.
Why it's wrong here
GetUserSPNs.py queries service principal names associated with standard domain user accounts for Kerberoasting attacks. Accounts lacking pre-authentication do not require SPNs to be targeted via AS-REP roasting, making this tool incorrect for this specific vulnerability phase.
- ✗
Capture an NTLMv1 challenge-response handshake by forcing authentication over SMB using Responder.
Why it's wrong here
Responder captures NetNTLM challenge-response, a different credential type requiring SMB coercion; the intercepted AS-REP is Kerberos material crackable directly with Hashcat mode 18200. Responder suits environments where SMB signing is disabled and no pre-auth-disabled accounts exist to harvest.
- ✗
Execute Hashcat with mode 13100 against the captured NTLM hash dumped from the local security authority subsystem service.
Why it's wrong here
Mode 13100 cracks Kerberos AS-REP roast hashes, not NTLM; the stem's captured AS-REP needs mode 18200, and no local SAM dump was performed. Mode 13100 suits scenarios where an attacker has extracted Kerberos ticket-granting material from a domain controller's memory or logs.
- ✓
Use GetNPUsers.py to request the AS-REP ticket and crack the derived hash offline using Hashcat mode 18200.
Why this is correct
With pre-authentication disabled, the domain controller returns an AS-REP encrypted with the user's password-derived key, so no valid credentials are needed. GetNPUsers.py harvests this ticket and extracts the crackable hash, which Hashcat mode 18200 attacks offline against wordlists, satisfying the efficiency constraint.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.