Courseiva
Kerberos Attacks →mediumMultiple Choice

GPEN Kerberos Attacks Practice Question

Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?

⚠ Common exam trap

Test-takers frequently believe the PAC is verified directly by client machines or member servers without KDC validation, misunderstanding where authorization data is processed and trusted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The PAC allows attackers to inject arbitrary group memberships into a forged ticket.

The PAC is a data structure embedded within Kerberos tickets that contains user identity and group membership information. Because the PAC is signed by the KDC, it is normally trusted. However, if an attacker can forge a ticket, they can also manipulate the PAC within that ticket to elevate their privileges, such as adding themselves to the 'Domain Admins' group, bypassing normal authorization checks completely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The PAC is always encrypted with the user's password, making it easy to crack.

    Why it's wrong here

    The PAC is not encrypted with the user's password. It is signed by the KDC using the KRBTGT account's key. While it contains user information, it is a protected part of the ticket structure, not a user-level credential that can be easily cracked via standard methods.

  • ✓

    The PAC allows attackers to inject arbitrary group memberships into a forged ticket.

    Why this is correct

    In a forgery scenario, the attacker controls the entire ticket construction, including the PAC. By modifying the PAC data, the attacker can grant themselves administrative group memberships, effectively becoming a domain administrator as far as any service accepting the ticket is concerned, regardless of their real identity.

  • ✗

    The PAC prevents the KDC from verifying the ticket's signature.

    Why it's wrong here

    The PAC is actually what the KDC uses to include authorization data in the ticket. It does not prevent signature verification; rather, it is part of the data that the KDC signs. The vulnerability arises when an attacker forges the entire ticket and signs it themselves.

  • ✗

    The PAC is required for TGT requests, making it a primary target for sniffers.

    Why it's wrong here

    The PAC is included in the TGS response, not the initial TGT request. While it is a target for manipulation, it is not simply 'sniffed' from the wire as it is encrypted within the ticket. The risk is specifically in the forgery and subsequent modification of the authorization data.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.