ISC2 CC Access Controls Concepts Practice Question
A security analyst is reviewing how a centralized authentication protocol validates user credentials before granting access to network resources. Which two characteristics correctly describe Kerberos authentication as used in a Windows domain environment? (Choose two.)
⚠ Common exam trap
The trap here is assuming that because tickets grant access, they must carry the user's password, when in fact Kerberos deliberately keeps passwords out of tickets and off the wire.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides mutual authentication, allowing both the client and the service to verify each other's identity.
Kerberos uses a trusted Key Distribution Center to issue ticket-granting and service tickets, and it supports mutual authentication because the service ticket is encrypted with the service key while the client's authenticator proves possession of the session key. Passwords are never sent to services or embedded in tickets, which is why the two selected characteristics accurately describe the protocol.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It requires every service to maintain a local copy of all domain user passwords.
Why it's wrong here
Kerberos removes the need for services to hold user passwords. Services share a secret only with the Key Distribution Center, and tickets encrypted with that secret prove the client's authorization. Replicating all domain passwords to every service would multiply exposure and contradict the protocol's centralized trust model, so this statement does not describe Kerberos.
- ✓
It provides mutual authentication, allowing both the client and the service to verify each other's identity.
Why this is correct
Kerberos supports mutual authentication because the service ticket is encrypted with the service's secret key, proving the ticket came from the Key Distribution Center, while the authenticator proves the client holds the session key. This lets both parties verify each other, which is valuable in domain environments where clients must be sure they are contacting a legitimate service and not an impostor.
- ✗
It stores user passwords in a reversible encrypted format inside each service ticket.
Why it's wrong here
Service tickets contain a session key and authorization data, not the user's password. Passwords are never embedded in tickets; the client's long-term key, derived from the password, is used only during the initial authentication exchange. Storing reversible passwords in tickets would create a serious exposure, and Kerberos is explicitly designed to avoid placing credentials in tickets.
- ✓
It uses a trusted third party called the Key Distribution Center to issue tickets.
Why this is correct
Kerberos relies on a Key Distribution Center, which includes the Authentication Server and the Ticket Granting Server. The client authenticates to the Authentication Server and receives a Ticket Granting Ticket, then requests service tickets from the Ticket Granting Server. This trusted third-party design means services can validate tickets without contacting a password store directly, which is central to how Kerberos works in a domain.
- ✗
It transmits the user's password to each service in plaintext during authentication.
Why it's wrong here
Kerberos is specifically designed to avoid sending passwords across the network. The client proves knowledge of the password-derived key by decrypting a challenge from the Authentication Server, and subsequent access uses tickets rather than the password. Sending plaintext passwords to each service would defeat the protocol's purpose and expose credentials to interception, so this statement is incorrect.
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.