CISSP Identity and Access Management Practice Question
A security analyst discovers that an attacker has gained domain admin privileges by forging a Kerberos TGT using the KRBTGT account hash. Which attack has occurred?
⚠ Common exam trap
CISSP often tests the distinction between Golden Ticket (KRBTGT hash, forges TGT, domain-wide) and Silver Ticket (service account hash, forges TGS, single service), so candidates who confuse the two ticket types pick the wrong answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Golden ticket attack
A Golden Ticket attack occurs when an attacker compromises the KRBTGT account's password hash and uses it to forge a legitimate-looking Kerberos Ticket Granting Ticket (TGT). Because the KRBTGT account signs all TGTs in the domain, a forged TGT is trusted by every Kerberos-enabled service, granting the attacker persistent domain-wide access — often as domain admin — without needing to authenticate normally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Golden ticket attack
Why this is correct
Forging a TGT with the KRBTGT account hash lets an attacker mint arbitrary Kerberos tickets, including domain admin privileges, without authenticating. This is the defining mechanism of a golden ticket, which grants persistent, forged access to the entire domain.
- ✗
Pass-the-ticket attack
Why it's wrong here
Pass-the-ticket reuses a legitimately issued, still-valid TGT or service ticket captured from memory; it does not fabricate one. Forging a TGT with the KRBTGT hash is a Golden Ticket attack. Pass-the-ticket fits scenarios where an attacker steals existing tickets via credential dumping.
- ✗
Silver ticket attack
Why it's wrong here
A silver ticket forges a service ticket using a service account hash, granting access to one service, not domain-wide rights. It is tempting because both abuse Kerberos tickets, and would be correct if the attacker had compromised a specific service account rather than KRBTGT.
- ✗
Kerberos brute force attack
Why it's wrong here
Brute force guesses credentials repeatedly; it cannot forge a TGT, which requires possession of the KRBTGT hash to encrypt a valid ticket. The forged-TGT technique is Golden Ticket. Brute forcing is tempting where weak or guessable passwords protect Kerberos pre-authentication, and lockout policies are absent.
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Kerberos
Kerberos is a network authentication protocol that uses tickets and symmetric-key cryptography to verify the identity of users and services in a secure, non-repudiable way.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.