Courseiva
Password Attacks →mediumMultiple Choice

PEN-200 Password Attacks Practice Question

During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?

⚠ Common exam trap

Students frequently confuse AS-REP Roasting with Kerberoasting, incorrectly looking for Service Principal Names (SPNs) instead of checking for the specific pre-authentication disabled attribute on user accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The account must have the 'Do not require Kerberos pre-authentication' option enabled.

AS-REP Roasting is possible when a user account has the 'Do not require Kerberos pre-authentication' attribute enabled in Active Directory. This allows an attacker to request a ticket for the user without needing the correct password, which can then be cracked offline. Understanding this specific AD attribute is critical for identifying vulnerable accounts during internal reconnaissance, as it represents a significant misconfiguration that simplifies the path to credential recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The account must have a Service Principal Name (SPN) set in the domain properties.

    Why it's wrong here

    Having an SPN set is the requirement for Kerberoasting, not AS-REP Roasting. AS-REP Roasting targets accounts regardless of whether they have an SPN, provided they have pre-authentication disabled. Confusing these two attacks is a common error that can lead to incorrect scoping of potential targets during an assessment.

  • ✓

    The account must have the 'Do not require Kerberos pre-authentication' option enabled.

    Why this is correct

    This setting is the primary vulnerability that makes AS-REP Roasting possible. When disabled, the domain controller sends an encrypted TGT without verifying the user's password first. This encrypted ticket can then be captured and cracked offline, making it a highly effective method for gaining access to user accounts.

  • ✗

    The user must be a member of the Domain Admins or Enterprise Admins group.

    Why it's wrong here

    Membership in privileged groups is not a technical requirement for AS-REP Roasting. Any account with the vulnerable setting enabled can be targeted, regardless of its permission level. While targeting administrators is more valuable, the attack's feasibility is strictly tied to the account's configuration, not its security group membership.

  • ✗

    The account must be configured with a password that has never been rotated.

    Why it's wrong here

    The age or rotation status of the password does not impact the vulnerability to AS-REP Roasting. The attack focuses on the pre-authentication setting. As long as the account exists and the pre-authentication flag is toggled, the account is vulnerable, regardless of how recently the password was updated or changed.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.