Courseiva

GPEN · topic practice

Kerberos Attacks practice questions

This domain covers abusing Kerberos authentication in Windows Active Directory: pre-auth weaknesses, ticket forgery, delegation misconfigurations, and service account cracking. GPEN questions present traffic captures, extracted hashes, or account attributes and require you to select the correct attack, tool, or defensive control rather than recall theory alone.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Kerberos Attacks

What the exam tests

What to know about Kerberos Attacks

You must map an observed Kerberos condition to the correct attack: AS-REP roasting, Kerberoasting, Silver/Golden Ticket, or delegation abuse. The critical skill is distinguishing which ticket type and hash source each scenario implies before choosing a tool or command.

Identifying AS-REP roasting when DONT_REQ_PREAUTH is set and extracting crackable hashes with GetNPUsers or Rubeus.

Forging Silver and Golden Tickets using service or krbtgt NTLM hashes, including PAC and SID manipulation.

Exploiting unconstrained, constrained, and resource-based constrained delegation via S4U2Self and S4U2Proxy.

Kerberoasting service accounts with SPNs using GetUserSPNs or Rubeus and cracking with Hashcat mode 13100.

Watch out for

Common Kerberos Attacks exam traps

  • ▸Confusing AS-REP roasting (no pre-auth required) with Kerberoasting (requires SPN and TGS request), leading to wrong tool selection.
  • ▸Assuming a Silver Ticket grants domain-wide access; it is scoped to the targeted service and its host, not the whole domain.
  • ▸Forgetting that gMSAs rotate passwords automatically, so Kerberoasting yields no crackable material for those accounts.

Practice set

Kerberos Attacks questions

20 questions · select your answer, then reveal the explanation

During a Golden Ticket attack, the attacker gains persistence by creating a forged TGT. What is required to successfully forge this ticket?

Which THREE of the following are critical steps in executing a Silver Ticket attack?

Which THREE of the following are viable defenses against Kerberoasting attacks?

Question 4mediummultiple choice
Read the full Kerberos Attacks explanation →

During an internal penetration test, an operator compromises a low-privileged Active Directory user account. The operator wants to extract password hashes for offline cracking without triggering account lockout policies or interacting with the Active Directory Domain Controller for every target account. Which attack technique should the operator execute against the domain?

Question 5mediummultiple choice
Read the full Kerberos Attacks explanation →

During an internal penetration test, an operator captures a single Kerberos AS-REQ for a domain user and notices the pre-authentication timestamp is encrypted with the user's long-term key. The operator wants to crack the user's password offline from this single capture. Which tool and technique should the operator use?

A tester has obtained the NTLM hash of a service account that is configured for constrained delegation to a backend SQL server. The tester wants to forge a service ticket that impersonates a domain administrator to access the SQL service, without contacting the KDC. Which approach should the tester use?

An operator has compromised a workstation and obtained a Kerberos TGT for a domain user. The operator wants to move laterally to a file server by abusing the user's group membership in a privileged group that has administrative rights on the server. Which artifact should the operator request and inject to achieve this without knowing the user's password?

You have compromised a domain controller and extracted the krbtgt account's NTLM hash. You want to create a Golden Ticket that grants you domain admin access for the next 10 years. Which tool and parameter would you use to forge this ticket with a 10-year lifetime?

An operator is performing a Kerberoasting attack against a domain and wants to maximize the chance of cracking service account passwords. Which two of the following actions should the operator take? (Choose two.)

Question 10mediummultiple choice
Read the full Kerberos Attacks explanation →

During a penetration test, an operator gains access to a domain controller and extracts the KRBTGT account's NTLM hash. The operator wants to create a Golden Ticket to maintain persistent access. Which tool and command should the operator use to forge a TGT with a 10-year lifetime?

An operator is attempting to Kerberoast a service account but finds that the extracted ticket is encrypted with AES256. The operator wants to crack the password offline. Which Hashcat mode should the operator use?

Question 12mediummultiple choice
Read the full Kerberos Attacks explanation →

An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?

Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?

Question 14mediummultiple choice
Read the full Kerberos Attacks explanation →

What is the primary security benefit of implementing Group Managed Service Accounts (gMSAs) in an environment vulnerable to Kerberoasting?

What is the fundamental difference between Golden Ticket and Silver Ticket attacks?

Question 16mediummultiple choice
Read the full Kerberos Attacks explanation →

Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?

Question 17mediummultiple choice
Read the full Kerberos Attacks explanation →

Which Kerberos feature is specifically exploited when an attacker uses 'constrained delegation' to escalate privileges?

What is the primary risk associated with 'Unconstrained Delegation' in Active Directory?

Question 19mediummultiple choice
Read the full Kerberos Attacks explanation →

What is the primary objective of a 'Kerberos Armoring' (FAST) implementation?

Question 20mediummultiple choice
Read the full Kerberos Attacks explanation →

Which of the following describes the 'AS-REP Roasting' attack?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Kerberos Attacks sessions

Start a Kerberos Attacks only practice session

Every question in these sessions is drawn from the Kerberos Attacks domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Kerberos Attacks?
You must map an observed Kerberos condition to the correct attack: AS-REP roasting, Kerberoasting, Silver/Golden Ticket, or delegation abuse. The critical skill is distinguishing which ticket type and hash source each scenario implies before choosing a tool or command.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Kerberos Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Kerberos Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.