GPEN Kerberos Attacks Practice Question
What is the primary risk associated with 'Unconstrained Delegation' in Active Directory?
⚠ Common exam trap
Candidates often confuse Unconstrained Delegation with Constrained Delegation. They incorrectly assume it involves the KDC directly or limits the service to specific target servers, missing the core risk of TGT caching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It allows the service to cache user TGTs, which can be extracted by an attacker.
In unconstrained delegation, a service account can take a user's TGT (which is sent to the service during authentication) and store it in its own memory. An attacker who compromises such a service can extract these stored TGTs. Because the TGT is valid for the whole domain, the attacker can then impersonate those users to any service in the domain, leading to total environment compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It forces the use of NTLM for all authentication requests.
Why it's wrong here
Unconstrained delegation has nothing to do with NTLM. It is a Kerberos-specific feature where a service is trusted to impersonate a user to any resource. The risk is specifically that the service receives and caches the user's TGT, making it accessible to any attacker.
- ✓
It allows the service to cache user TGTs, which can be extracted by an attacker.
Why this is correct
Unconstrained delegation causes the KDC to send the user's TGT to the service along with the TGS. The service caches this TGT in memory. An attacker with administrative access to that machine can dump the memory, retrieve the TGT, and use it to impersonate users anywhere.
- ✗
It requires the domain controller to store plaintext passwords for all users.
Why it's wrong here
The domain controller never stores plaintext passwords. It stores hashes. Unconstrained delegation is a configuration attribute on a computer or user object in AD, and it does not impact how the domain controller stores or handles user credentials or password data.
- ✗
It prevents the KDC from enforcing password expiration policies.
Why it's wrong here
Delegation settings are entirely separate from password expiration policies. An account with unconstrained delegation enabled is still subject to the same domain-wide password policies as any other account. The risk is strictly limited to the handling of TGTs during the authentication process.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.