Courseiva
Advanced Password Attacks →mediumMultiple Choice

GPEN Advanced Password Attacks Practice Question

Which of the following is a primary advantage of using a 'Golden Ticket' attack over other credential-based attacks?

⚠ Common exam trap

Candidates often assume the Golden Ticket gives access to a specific user's credentials. They fail to grasp that the ticket is forged for the KRBTGT account, granting domain-wide, persistent, and forged identity access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides persistent access even after the user changes their password.

A Golden Ticket attack involves the compromise of the KRBTGT account, which is the master account for the Kerberos service in a domain. This allows an attacker to forge TGTs that can request access to any resource. Because the attacker controls the TGT, they can grant themselves administrative privileges and bypass standard password changes, making it a highly persistent and difficult-to-detect method of maintaining domain control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It does not require administrative privileges to execute.

    Why it's wrong here

    Creating a Golden Ticket requires knowledge of the KRBTGT account's NTLM hash. Obtaining this hash requires Domain Admin-level access to the domain controller. Therefore, it is impossible to perform this attack without having already compromised the highest level of authority in the Active Directory domain environment.

  • ✓

    It provides persistent access even after the user changes their password.

    Why this is correct

    Because the Golden Ticket is a forged TGT, it is independent of individual user accounts or passwords. Even if an administrator changes their password or resets their account, the attacker can continue to use the forged ticket to access resources until the KRBTGT password itself is reset.

  • ✗

    It is easily detectable by standard antivirus software.

    Why it's wrong here

    Golden Ticket attacks are notoriously difficult to detect because they leverage native Kerberos authentication traffic. Antivirus software typically looks for malicious binaries or behavioral anomalies, but the use of a forged ticket appears as legitimate authentication, making it a favorite technique for advanced persistent threats seeking long-term access.

  • ✗

    It is limited to a single service on the network.

    Why it's wrong here

    A Golden Ticket is not limited to a single service. It is a TGT that can be used to request service tickets for any resource in the domain. This makes it a 'keys to the kingdom' attack, granting the attacker access to everything from file shares to domain controllers.

About these practice questions

Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.