Courseiva

CISSP Identity and Access Management Practice Question

A security analyst discovers that an attacker has gained domain admin privileges by forging a Kerberos TGT using the KRBTGT account hash. Which attack has occurred?

⚠ Common exam trap

CISSP often tests the distinction between Golden Ticket (KRBTGT hash, forges TGT, domain-wide) and Silver Ticket (service account hash, forges TGS, single service), so candidates who confuse the two ticket types pick the wrong answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Golden ticket attack

A Golden Ticket attack occurs when an attacker compromises the KRBTGT account's password hash and uses it to forge a legitimate-looking Kerberos Ticket Granting Ticket (TGT). Because the KRBTGT account signs all TGTs in the domain, a forged TGT is trusted by every Kerberos-enabled service, granting the attacker persistent domain-wide access — often as domain admin — without needing to authenticate normally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Golden ticket attack

    Why this is correct

    Forging a TGT with the KRBTGT account hash lets an attacker mint arbitrary Kerberos tickets, including domain admin privileges, without authenticating. This is the defining mechanism of a golden ticket, which grants persistent, forged access to the entire domain.

  • ✗

    Pass-the-ticket attack

    Why it's wrong here

    Pass-the-ticket reuses a legitimately issued, still-valid TGT or service ticket captured from memory; it does not fabricate one. Forging a TGT with the KRBTGT hash is a Golden Ticket attack. Pass-the-ticket fits scenarios where an attacker steals existing tickets via credential dumping.

  • ✗

    Silver ticket attack

    Why it's wrong here

    A silver ticket forges a service ticket using a service account hash, granting access to one service, not domain-wide rights. It is tempting because both abuse Kerberos tickets, and would be correct if the attacker had compromised a specific service account rather than KRBTGT.

  • ✗

    Kerberos brute force attack

    Why it's wrong here

    Brute force guesses credentials repeatedly; it cannot forge a TGT, which requires possession of the KRBTGT hash to encrypt a valid ticket. The forged-TGT technique is Golden Ticket. Brute forcing is tempting where weak or guessable passwords protect Kerberos pre-authentication, and lockout policies are absent.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.