SC-200 Perform threat hunting Practice Question
Which TWO of the following are valid methods to detect Kerberoasting attacks during a threat hunt? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service account logon events with RC4 encryption type.
Option A is correct because Kerberoasting requests TGS tickets for service accounts and the attacker typically requests RC4 (etype 0x17) encryption to make offline cracking of the service account hash easier, so service account logon events showing RC4 encryption (Event ID 4769 with Ticket Encryption Type 0x17) are a strong hunting indicator. Option B is correct because a single user account rapidly requesting multiple TGS tickets for many different service accounts (SPNs) is a hallmark of automated Kerberoasting enumeration and ticket harvesting. Option C is not specific to Kerberoasting, since LDAP query volume anomalies can reflect many other reconnaissance or administrative activities. Option D concerns NTLM authentication failures, which are unrelated to Kerberos TGS abuse. Option E describes Golden Ticket detection, which involves forged TGTs and KRBTGT compromise, not Kerberoasting's TGS request behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Service account logon events with RC4 encryption type.
Why this is correct
Kerberoasting requests RC4-encrypted service tickets, so hunting for service account logon events showing RC4 (0x17) encryption type exposes the attack, since legitimate modern service authentication typically negotiates AES. This satisfies the stem's detection requirement by targeting the encryption downgrade inherent to extracting crackable ticket hashes.
- ✓
Multiple Kerberos TGS requests from a single user account to multiple service accounts.
Why this is correct
Multiple TGS requests from one account across many service accounts expose Kerberoasting's enumeration phase, where attackers harvest service principal names before cracking their tickets offline. This behaviour satisfies the hunt's detection requirement by surfacing abnormal ticket-granting volume, which legitimate single-service access rarely produces.
- ✗
Unusual number of LDAP queries from a domain controller.
Why it's wrong here
Domain controllers perform LDAP queries constantly for directory operations, so volume alone lacks the specificity Kerberoasting detection needs. This metric suits hunting directory enumeration or reconnaissance. Kerberoasting is identified by abnormal Kerberos service ticket requests, particularly RC4 encryption, for accounts with registered SPNs.
- ✗
High volume of NTLM authentication failures from a single IP.
Why it's wrong here
NTLM authentication failures indicate credential attacks such as password spraying, not Kerberoasting. Kerberoasting requests Kerberos service tickets (TGS) for accounts with SPNs, then cracks them offline; detection relies on anomalous RC4 TGS requests, not NTLM failures. NTLM failure monitoring suits brute-force or spraying hunts.
- ✗
Detection of forged Kerberos tickets (Golden Ticket) in the domain.
Why it's wrong here
Golden Ticket detection targets forged TGTs signed with a stolen KRBTGT key, a persistence technique following domain compromise, not the RC4 service-ticket requests that characterise Kerberoasting. It belongs in hunts for domain-wide forgery; Kerberoasting instead shows anomalous TGS requests for accounts with SPNs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.