Courseiva
Access Controls →mediumMultiple Choice

SSCP Access Controls Practice Question

An organization uses Kerberos for SSO. A user reports that after entering their password, they receive a 'ticket expired' error when trying to access a network share. The system administrator checks the Kerberos configuration. Which ticket is most likely expired?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ticket-Granting Ticket (TGT)

The Ticket-Granting Ticket (TGT) has a limited lifetime (typically 8-10 hours). When it expires, the user must re-authenticate to get a new TGT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Session key

    Why it's wrong here

    A session key is symmetric key material shared between client and service, not a ticket with its own lifetime; it cannot independently expire and trigger this error. Session keys matter when encryption or integrity checks fail, not when a ticket's validity window lapses.

  • ✓

    Ticket-Granting Ticket (TGT)

    Why this is correct

    The Ticket-Granting Ticket is obtained at initial authentication and used to request service tickets. If it expires, subsequent access to the network share fails with a ticket expired error, matching the stem's symptom after password entry.

  • ✗

    Service ticket

    Why it's wrong here

    A service ticket is issued per-service after the TGT is presented, so an expired one would block access to that specific share while other services still work. It is tempting because the error names a ticket, yet the TGT is what expires first and would prevent obtaining any service ticket at all.

  • ✗

    Authentication Server (AS) reply

    Why it's wrong here

    The AS reply is the TGT returned after password authentication; it is cached and used to request service tickets, so its expiry would surface before or during initial authentication, not on accessing a share. It matters when the TGT lifetime or clock skew blocks new ticket requests.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.