SSCP Access Controls Practice Question
In a Kerberos environment, what is the primary function of the Ticket Granting Ticket (TGT)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To request service tickets from the Ticket Granting Service (TGS)
The TGT is obtained after initial authentication and is used to request service tickets for various resources without re-authenticating.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To store the user's password hash securely
Why it's wrong here
Kerberos never stores password hashes in tickets; the client derives a key from the password to decrypt the AS reply, and the KDC holds the long-term key. It is tempting because the TGT is encrypted with that key, and storing credential material would be correct for a password vault, not a Kerberos ticket.
- ✓
To request service tickets from the Ticket Granting Service (TGS)
Why this is correct
After initial authentication, the client presents its TGT to the Ticket Granting Service. The TGS validates that ticket and issues service tickets for specific resources, so the TGT acts as the credential enabling service ticket requests without re-entering credentials.
- ✗
To provide a session key for encrypting communications
Why it's wrong here
The session key is generated by the KDC and delivered inside the TGT and service tickets; the TGT's function is to obtain further service tickets without re-entering credentials. It is tempting because session keys travel within tickets, and issuing a session key would be correct for the authenticator exchange with a service.
- ✗
To authenticate the user to the Key Distribution Center (KDC)
Why it's wrong here
The TGT is a credential presented to the Ticket Granting Service to obtain service tickets; the user authenticates to the KDC during the initial AS exchange, before the TGT exists. It is tempting because the TGT proves prior authentication, and it would be correct if the question asked what the KDC issues after verifying credentials.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.