GPEN Kerberos Attacks Practice Question
During an internal penetration test, you have obtained cleartext credentials for a low-privileged Active Directory user. You want to enumerate which user accounts do not require Kerberos preauthentication so you can request AS-REP messages and crack them offline. Which Impacket tool and command should you use?
⚠ Common exam trap
Test-takers frequently confuse AS-REP Roasting with Kerberoasting; both involve requesting encrypted tickets for offline cracking, but they target different account configurations and use different Impacket scripts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GetNPUsers.py -request -dc-ip 10.0.0.1 domain/user:password
AS-REP Roasting targets accounts that have Kerberos preauthentication disabled. The Impacket script GetNPUsers.py with the -request flag queries the domain for such accounts and requests an AS-REP for each, which can then be cracked offline. The other tools serve different purposes: GetUserSPNs.py is for Kerberoasting, secretsdump.py extracts secrets from hosts, and ticketer.py forges tickets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ticketer.py -nthash <hash> -domain domain.local -dc-ip 10.0.0.1 user
Why it's wrong here
ticketer.py is used to forge Kerberos tickets, such as Golden or Silver Tickets, given the appropriate key material (e.g., krbtgt hash or service account hash). It does not enumerate preauthentication settings or request AS-REP messages. This tool is for persistence or privilege escalation after compromising key material, not for the reconnaissance and extraction step of AS-REP Roasting.
- ✓
GetNPUsers.py -request -dc-ip 10.0.0.1 domain/user:password
Why this is correct
GetNPUsers.py is the Impacket tool specifically built for AS-REP Roasting. With the -request flag, it queries Active Directory for accounts where the 'Do not require Kerberos preauthentication' flag is set, then sends an AS-REQ for each and captures the returned AS-REP, which is encrypted with the user's password hash. This aligns exactly with your goal of enumerating and extracting crackable AS-REP messages.
- ✗
GetUserSPNs.py -request -dc-ip 10.0.0.1 domain/user:password
Why it's wrong here
GetUserSPNs.py is designed for Kerberoasting, not AS-REP Roasting. It requests service tickets (TGS) for accounts with SPNs, which are encrypted with the service account's NTLM hash. This does not target accounts that lack preauthentication; instead, it targets accounts with SPNs. Using this tool here would not enumerate or request AS-REP messages for the users you are looking for.
- ✗
secretsdump.py domain/user:password@10.0.0.1
Why it's wrong here
secretsdump.py is used to extract credential material such as NTLM hashes, Kerberos keys, and LSA secrets from a target system, often via DCSync or remote registry. It does not enumerate accounts lacking preauthentication nor request AS-REP messages. While it can dump hashes, it requires higher privileges and does not perform the offline cracking step you need for AS-REP Roasting.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.