Courseiva
Kerberos Attacks →hardMultiple Choice

GPEN Kerberos Attacks Practice Question

You have compromised a workstation and extracted the NTLM hash of a service account that is configured for unconstrained delegation. You want to craft a Silver Ticket to impersonate a domain administrator when accessing a specific file server. Which piece of information is absolutely required to forge this ticket?

⚠ Common exam trap

The trap here is mixing up the key material needed for a Silver Ticket versus a Golden Ticket; the Silver Ticket uses the service account's key, not the krbtgt key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The service account's NTLM hash or Kerberos key

To forge a Silver Ticket, the attacker must have the target service account's NTLM hash or Kerberos key to encrypt the service ticket. The domain SID and user RID are needed for the PAC but are not the encryption key. A TGT is not required because the ticket is presented directly to the service. The krbtgt hash is for Golden Tickets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The domain SID and the target user's RID

    Why it's wrong here

    The domain SID and a user RID are used to populate the PAC inside the ticket to specify the identity and group memberships. While these are important for the ticket's authorization data, they are not the cryptographic key required to encrypt and sign the ticket. Without the service account's key, the ticket cannot be forged; the SID and RID alone are insufficient.

  • ✗

    A valid TGT for the service account

    Why it's wrong here

    A Silver Ticket is a forged TGS that is presented directly to the service; it does not require a legitimate TGT. In fact, the attack bypasses the KDC entirely, so having a TGT for the service account is unnecessary and would not help in forging the ticket. The TGT is used for Golden Ticket attacks, not Silver Tickets.

  • ✓

    The service account's NTLM hash or Kerberos key

    Why this is correct

    A Silver Ticket is a forged service ticket (TGS) encrypted with the target service account's key. To create it, you need the NTLM hash or Kerberos key (AES) of the account under which the service runs. In this scenario, you have the service account's NTLM hash, which is exactly what is needed to encrypt the ticket and have it accepted by the file server without contacting the KDC.

  • ✗

    The krbtgt account's NTLM hash

    Why it's wrong here

    The krbtgt hash is required for forging a Golden Ticket, which grants access to any service in the domain by creating a TGT. For a Silver Ticket, you only need the service account's hash (or the machine account hash for the target service) to encrypt the service ticket. Using the krbtgt hash would be overkill and is not necessary for a Silver Ticket targeting a single service.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.