Courseiva
Active Directory Attacks →easyMultiple Choice

PEN-200 Active Directory Attacks Practice Question

What is the primary objective of an 'AS-REP Roasting' attack?

⚠ Common exam trap

Candidates often confuse AS-REP Roasting with Kerberoasting. AS-REP Roasting specifically targets accounts where Kerberos preauthentication is disabled, allowing the request of a TGT without knowing the user's password.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To crack the password of an account without preauth

AS-REP Roasting targets user accounts where Kerberos preauthentication is disabled. By sending an AS-REQ without preauthentication, the domain controller returns an AS-REP containing a TGT encrypted with the user's password hash. The attacker can then extract this hash and perform offline brute-force cracking to recover the user's cleartext password. This is highly effective against service accounts that have been misconfigured to skip preauthentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To capture the KRBTGT hash from the domain controller

    Why it's wrong here

    Capturing the KRBTGT hash requires elevated privileges on a domain controller, usually via DCSync or credential dumping. AS-REP Roasting is an unauthenticated or low-privilege attack that targets individual user accounts. It does not grant access to the domain-wide KRBTGT secret or facilitate a Golden Ticket attack directly.

  • ✓

    To crack the password of an account without preauth

    Why this is correct

    AS-REP Roasting exploits accounts with the 'Do not require Kerberos preauthentication' flag. By requesting a ticket without providing preauthentication data, the attacker receives a response encrypted with the user's hash, which can be cracked offline to reveal the cleartext password, regardless of the password's complexity or length.

  • ✗

    To bypass the need for an NTLM hash during relay

    Why it's wrong here

    AS-REP Roasting is a Kerberos-based attack and does not involve NTLM relaying. Relay attacks require intercepting and forwarding authentication requests to another service, whereas AS-REP Roasting is an offline analysis of intercepted Kerberos packets designed to recover cleartext credentials for a specific, misconfigured domain user account.

  • ✗

    To escalate privileges via a forged Kerberos ticket

    Why it's wrong here

    AS-REP Roasting recovers a user's password, which may lead to escalation, but it does not involve forging a ticket. A Silver or Golden Ticket involves forging a ticket manually; AS-REP Roasting is about obtaining a piece of encrypted data from the DC to crack, not about creating forged authentication tokens.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.