Courseiva
Kerberos Attacks →mediumMultiple Choice

GPEN Kerberos Attacks Practice Question

During an internal penetration test, you have obtained cleartext credentials for a low-privileged Active Directory user. You want to enumerate which user accounts do not require Kerberos preauthentication so you can request AS-REP messages and crack them offline. Which Impacket tool and command should you use?

⚠ Common exam trap

Test-takers frequently confuse AS-REP Roasting with Kerberoasting; both involve requesting encrypted tickets for offline cracking, but they target different account configurations and use different Impacket scripts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GetNPUsers.py -request -dc-ip 10.0.0.1 domain/user:password

AS-REP Roasting targets accounts that have Kerberos preauthentication disabled. The Impacket script GetNPUsers.py with the -request flag queries the domain for such accounts and requests an AS-REP for each, which can then be cracked offline. The other tools serve different purposes: GetUserSPNs.py is for Kerberoasting, secretsdump.py extracts secrets from hosts, and ticketer.py forges tickets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ticketer.py -nthash <hash> -domain domain.local -dc-ip 10.0.0.1 user

    Why it's wrong here

    ticketer.py is used to forge Kerberos tickets, such as Golden or Silver Tickets, given the appropriate key material (e.g., krbtgt hash or service account hash). It does not enumerate preauthentication settings or request AS-REP messages. This tool is for persistence or privilege escalation after compromising key material, not for the reconnaissance and extraction step of AS-REP Roasting.

  • ✓

    GetNPUsers.py -request -dc-ip 10.0.0.1 domain/user:password

    Why this is correct

    GetNPUsers.py is the Impacket tool specifically built for AS-REP Roasting. With the -request flag, it queries Active Directory for accounts where the 'Do not require Kerberos preauthentication' flag is set, then sends an AS-REQ for each and captures the returned AS-REP, which is encrypted with the user's password hash. This aligns exactly with your goal of enumerating and extracting crackable AS-REP messages.

  • ✗

    GetUserSPNs.py -request -dc-ip 10.0.0.1 domain/user:password

    Why it's wrong here

    GetUserSPNs.py is designed for Kerberoasting, not AS-REP Roasting. It requests service tickets (TGS) for accounts with SPNs, which are encrypted with the service account's NTLM hash. This does not target accounts that lack preauthentication; instead, it targets accounts with SPNs. Using this tool here would not enumerate or request AS-REP messages for the users you are looking for.

  • ✗

    secretsdump.py domain/user:password@10.0.0.1

    Why it's wrong here

    secretsdump.py is used to extract credential material such as NTLM hashes, Kerberos keys, and LSA secrets from a target system, often via DCSync or remote registry. It does not enumerate accounts lacking preauthentication nor request AS-REP messages. While it can dump hashes, it requires higher privileges and does not perform the offline cracking step you need for AS-REP Roasting.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.