PEN-200 Active Directory Attacks Practice Question
During an Active Directory penetration test, you have obtained Domain Admin privileges. To maintain persistent access, you decide to create a Golden Ticket. Which two of the following pieces of information are required to forge a valid Golden Ticket? (Choose two.)
⚠ Common exam trap
The trap here is thinking that a Golden Ticket requires a legitimate TGT or user password, when in fact it is forged using the KRBTGT hash and domain SID.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The KRBTGT account's NTLM hash.
To forge a Golden Ticket, you need the KRBTGT account's NTLM hash to encrypt the ticket and the domain SID to populate the PAC correctly. These two elements allow you to create a TGT for any user, granting persistent domain-wide access. Other items like a valid TGT or user passwords are not required, as the ticket is self-signed with the KRBTGT hash.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The target user's password.
Why it's wrong here
The target user's password is not required to forge a Golden Ticket. The ticket is encrypted with the KRBTGT hash, not the user's password. The attacker can specify any username in the ticket, so knowing the password is irrelevant. This option confuses Golden Ticket creation with other credential-based attacks.
- ✓
The KRBTGT account's NTLM hash.
Why this is correct
The KRBTGT account's NTLM hash is used to encrypt and sign the Golden Ticket. Without it, the ticket cannot be forged because the KDC uses this hash to validate TGTs. This is a core requirement for creating a Golden Ticket, as it allows the attacker to mint TGTs for any user, including Domain Admins.
- ✗
A valid Kerberos TGT for a Domain Admin.
Why it's wrong here
A Golden Ticket is forged, not obtained from the KDC. You do not need a valid TGT; instead, you use the KRBTGT hash to create one. This option misrepresents the nature of Golden Tickets, which are self-signed TGTs. Having a legitimate TGT is unnecessary and would defeat the purpose of persistence.
- ✗
The Domain Controller's machine account hash.
Why it's wrong here
The Domain Controller's machine account hash is not needed for a Golden Ticket. While it could be used for a Silver Ticket targeting services on that DC, Golden Tickets rely on the KRBTGT hash. This option is a common misconception, conflating different ticket forging techniques.
- ✓
The domain's SID.
Why this is correct
The domain SID is embedded in the Golden Ticket's PAC and is used to identify the domain and construct the user's SID. It is essential for the ticket to be accepted by the KDC and for proper authorization. Without the correct domain SID, the ticket would be invalid or not grant the intended privileges.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.