PEN-200 Password Attacks Practice Question
During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?
⚠ Common exam trap
Students frequently confuse AS-REP Roasting with Kerberoasting, incorrectly looking for Service Principal Names (SPNs) instead of checking for the specific pre-authentication disabled attribute on user accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The account must have the 'Do not require Kerberos pre-authentication' option enabled.
AS-REP Roasting is possible when a user account has the 'Do not require Kerberos pre-authentication' attribute enabled in Active Directory. This allows an attacker to request a ticket for the user without needing the correct password, which can then be cracked offline. Understanding this specific AD attribute is critical for identifying vulnerable accounts during internal reconnaissance, as it represents a significant misconfiguration that simplifies the path to credential recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The account must have a Service Principal Name (SPN) set in the domain properties.
Why it's wrong here
Having an SPN set is the requirement for Kerberoasting, not AS-REP Roasting. AS-REP Roasting targets accounts regardless of whether they have an SPN, provided they have pre-authentication disabled. Confusing these two attacks is a common error that can lead to incorrect scoping of potential targets during an assessment.
- ✓
The account must have the 'Do not require Kerberos pre-authentication' option enabled.
Why this is correct
This setting is the primary vulnerability that makes AS-REP Roasting possible. When disabled, the domain controller sends an encrypted TGT without verifying the user's password first. This encrypted ticket can then be captured and cracked offline, making it a highly effective method for gaining access to user accounts.
- ✗
The user must be a member of the Domain Admins or Enterprise Admins group.
Why it's wrong here
Membership in privileged groups is not a technical requirement for AS-REP Roasting. Any account with the vulnerable setting enabled can be targeted, regardless of its permission level. While targeting administrators is more valuable, the attack's feasibility is strictly tied to the account's configuration, not its security group membership.
- ✗
The account must be configured with a password that has never been rotated.
Why it's wrong here
The age or rotation status of the password does not impact the vulnerability to AS-REP Roasting. The attack focuses on the pre-authentication setting. As long as the account exists and the pre-authentication flag is toggled, the account is vulnerable, regardless of how recently the password was updated or changed.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.