Courseiva

GPEN Advanced Password Attacks Practice Question

When conducting an advanced credential harvesting assessment against an Active Directory environment, a penetration tester attempts Kerberoasting. Which TWO actions or conditions are required to successfully extract and crack service tickets using this technique? (Choose TWO)

⚠ Common exam trap

Many students incorrectly assume that administrative domain credentials are required to request service tickets, forgetting that any standard domain user account can request SPN tickets by design.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Possession of a standard domain user account to request service tickets from the Key Distribution Center.

Kerberoasting requires requesting a Ticket Granting Service ticket for any domain user account associated with a Service Principal Name, followed by offline cracking since the ticket is encrypted with the service account password hash. GPEN testers leverage this to extract credentials without touching the target server directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Possession of a standard domain user account to request service tickets from the Key Distribution Center.

    Why this is correct

    Any authenticated domain user possesses the rights to request a Ticket Granting Service ticket for any valid Service Principal Name registered in Active Directory. This core protocol design feature allows standard low-privilege accounts to initiate the Kerberoasting attack chain.

  • ✗

    Direct administrative access to the primary Domain Controller file system to steal the NTDS.dit database.

    Why it's wrong here

    Kerberoasting requests service tickets over the network using any domain user credentials; NTDS.dit theft is a separate offline attack requiring Domain Controller access. It is tempting because both harvest credentials, and NTDS.dit extraction would be the correct approach when full domain hash dumping is the objective.

  • ✗

    An active session running specialized exploitation tools on the specific host running the target service.

    Why it's wrong here

    Kerberoasting only needs any authenticated domain account to request a service ticket and extract its encrypted portion; the tooling runs on the attacker's own machine, not the service host. It is tempting because host-level access is required for other credential attacks, such as dumping LSASS memory.

  • ✓

    Offline brute-force cracking of the captured Ticket Granting Service ticket using tools like Hashcat or John the Ripper.

    Why this is correct

    Because the service ticket is encrypted with the target service account's password hash, extracting the plaintext password requires offline brute-forcing or dictionary attacks against the ticket blob. Tools like Hashcat mode 13100 process these specific ticket formats efficiently.

  • ✗

    Unconstrained Kerberos delegation configured specifically on the local workstation operating system.

    Why it's wrong here

    Unconstrained delegation lets a compromised host capture TGTs, but Kerberoasting exploits RC4-encrypted service tickets requested from any authenticated context, so no delegation setting is involved. It is tempting because delegation misconfigurations are genuine privilege-escalation vectors, just not this one.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.