GPEN Kerberos Attacks Practice Question
Which of the following describes the 'AS-REP Roasting' attack?
⚠ Common exam trap
Many candidates confuse AS-REP Roasting with Kerberoasting. They incorrectly believe it involves requesting service tickets from the KDC, failing to realize it specifically targets accounts where pre-authentication is disabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It allows an attacker to crack user account passwords for accounts without pre-authentication.
AS-REP Roasting targets user accounts that have 'Do not require Kerberos preauthentication' enabled. An attacker can request a TGT for such an account without providing a password. The KDC responds with an encrypted ticket (the AS-REP) that the attacker can then extract and crack offline, similar to how Kerberoasting works, to obtain the user's plaintext password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It targets service accounts that are configured with SPNs.
Why it's wrong here
AS-REP Roasting exploits accounts with Kerberos pre-authentication disabled, requesting an AS-REP and cracking the encrypted portion offline; SPNs are irrelevant, since SPN-bearing service accounts are the target of Kerberoasting instead. It is tempting because both attacks abuse Kerberos ticket requests and yield crackable hashes, but the enabling condition differs.
- ✗
It relies on the interception of a TGS request to obtain encrypted credentials.
Why it's wrong here
AS-REP Roasting targets the AS-REQ/AS-REP exchange (initial authentication), not the TGS-REQ/TGS-REP exchange. The vulnerability is the lack of pre-authentication, which allows the attacker to obtain an encrypted blob that can be cracked offline without needing any initial credentials.
- ✓
It allows an attacker to crack user account passwords for accounts without pre-authentication.
Why this is correct
When pre-authentication is disabled, the KDC will provide an AS-REP ticket to anyone who asks. This ticket is encrypted with the user's password. The attacker can capture this response and perform an offline brute-force attack to recover the original password.
- ✗
It is a technique for escalating privileges using the KRBTGT account.
Why it's wrong here
AS-REP Roasting is used to obtain the password of a specific user account, not to escalate privileges via the KRBTGT account. Golden Ticket attacks are the technique that uses the KRBTGT account to forge administrative TGTs for domain-wide access.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.