GPEN Kerberos Attacks Practice Question
Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?
⚠ Common exam trap
Candidates often confuse Kerberoasting indicators with AS-REP roasting indicators, mistakenly looking for pre-authentication disabled flags instead of high-volume TGS-REQ packets and weak encryption types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multiple TGS-REQ packets from a single workstation targeting various SPNs within a short timeframe.
Kerberoasting is characterized by the bulk request of service tickets and the subsequent offline cracking of the service account's password. Detectors look for anomalous TGS-REQ volume and specific encryption types (like RC4-HMAC) in the requests. Identifying these patterns allows security analysts to pinpoint service accounts that are currently under attack, enabling timely password resets or the implementation of Group Managed Service Accounts (gMSAs) to mitigate future risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Multiple TGS-REQ packets from a single workstation targeting various SPNs within a short timeframe.
Why this is correct
A high volume of TGS-REQ requests from a single source is a hallmark of Kerberoasting, as the attacker attempts to collect multiple tickets to maximize their chances of cracking service account passwords. This behavioral pattern is distinct from normal network activity where users typically request tickets incrementally.
- ✗
A sudden spike in AS-REQ events using expired Kerberos TGTs.
Why it's wrong here
AS-REQ events relate to initial authentication. While expired tickets can cause issues, they are not a primary indicator of Kerberoasting. The focus of Kerberoasting is on TGS-REQ events, which occur after the user has already obtained a valid TGT from the KDC.
- ✓
The use of RC4-HMAC encryption in service ticket requests for accounts that support AES.
Why this is correct
Attackers often force the use of RC4-HMAC (encryption type 0x17) because it is significantly faster to crack offline compared to AES-128 or AES-256. If a service account is configured for AES but receives TGS-REQ requests using RC4, it is a strong indicator of malicious intent.
- ✗
Frequent failed logins followed by a successful Kerberos authentication.
Why it's wrong here
Failed logins are typically associated with brute-force password attacks or credential stuffing, not Kerberoasting. Kerberoasting does not require knowledge of the account password to generate a ticket request, so it generally does not trigger account lockout mechanisms unless the attacker is also attempting other methods.
- ✗
An influx of TGT-REQ packets originating from non-domain controllers.
Why it's wrong here
TGT requests occur constantly in a Windows domain as clients authenticate to the KDC. TGT requests themselves are not inherently malicious. Kerberoasting specifically targets the TGS-REQ phase of the authentication flow, making TGT-REQ volume an unreliable metric for identifying this specific class of attack.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.