GPEN Kerberos Attacks Practice Question
Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?
⚠ Common exam trap
Test-takers frequently believe the PAC is verified directly by client machines or member servers without KDC validation, misunderstanding where authorization data is processed and trusted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The PAC allows attackers to inject arbitrary group memberships into a forged ticket.
The PAC is a data structure embedded within Kerberos tickets that contains user identity and group membership information. Because the PAC is signed by the KDC, it is normally trusted. However, if an attacker can forge a ticket, they can also manipulate the PAC within that ticket to elevate their privileges, such as adding themselves to the 'Domain Admins' group, bypassing normal authorization checks completely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The PAC is always encrypted with the user's password, making it easy to crack.
Why it's wrong here
The PAC is not encrypted with the user's password. It is signed by the KDC using the KRBTGT account's key. While it contains user information, it is a protected part of the ticket structure, not a user-level credential that can be easily cracked via standard methods.
- ✓
The PAC allows attackers to inject arbitrary group memberships into a forged ticket.
Why this is correct
In a forgery scenario, the attacker controls the entire ticket construction, including the PAC. By modifying the PAC data, the attacker can grant themselves administrative group memberships, effectively becoming a domain administrator as far as any service accepting the ticket is concerned, regardless of their real identity.
- ✗
The PAC prevents the KDC from verifying the ticket's signature.
Why it's wrong here
The PAC is actually what the KDC uses to include authorization data in the ticket. It does not prevent signature verification; rather, it is part of the data that the KDC signs. The vulnerability arises when an attacker forges the entire ticket and signs it themselves.
- ✗
The PAC is required for TGT requests, making it a primary target for sniffers.
Why it's wrong here
The PAC is included in the TGS response, not the initial TGT request. While it is a target for manipulation, it is not simply 'sniffed' from the wire as it is encrypted within the ticket. The risk is specifically in the forgery and subsequent modification of the authorization data.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.