PEN-200 Active Directory Attacks Practice Question
Which of the following describes the primary difference between a Golden Ticket and a Silver Ticket attack in an Active Directory environment?
⚠ Common exam trap
Candidates often believe both tickets provide identical access. However, Golden tickets grant domain-wide persistence via the KRBTGT account, while Silver tickets are limited to specific services, offering less overall control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Golden tickets require the KRBTGT hash, while Silver tickets require a service account hash.
The distinction between Golden and Silver tickets is fundamental to understanding post-exploitation persistence. Golden tickets involve the KRBTGT account, granting access to the entire domain, while Silver tickets target specific service accounts. Mastering this difference is essential for determining the scope of an attack and the level of stealth required, as Silver tickets are often safer to deploy as they avoid triggering certain domain controller alerts related to TGT requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Golden tickets are for NTLM, whereas Silver tickets are for Kerberos.
Why it's wrong here
Both Golden and Silver tickets are exclusively Kerberos-based attacks. NTLM attacks, such as Pass-the-Hash, function differently and do not involve generating forged Kerberos tickets. The ticket concept is tied strictly to the Kerberos protocol's reliance on trusted third-party authentication via the Key Distribution Center and service-specific keys.
- ✓
Golden tickets require the KRBTGT hash, while Silver tickets require a service account hash.
Why this is correct
Golden tickets require the hash of the KRBTGT account, which allows the forging of TGTs for any resource. Silver tickets require the hash of a specific service account (e.g., MSSQL or CIFS), allowing the forgery of TGS tickets for that specific service, which is much more targeted and quieter.
- ✗
Silver tickets grant domain admin access, while Golden tickets are restricted to workstations.
Why it's wrong here
The inverse is true. Golden tickets grant comprehensive access across the entire domain by spoofing authentication to the domain controller, while Silver tickets are confined to the specific service for which the ticket was forged. Confusing the two would lead to significantly incorrect assumptions regarding access control and privilege levels.
- ✗
Only Silver tickets require active communication with the Domain Controller.
Why it's wrong here
Neither attack requires active communication with the domain controller once the necessary hash is obtained. Both tickets are forged offline and then presented directly to the target service or the ticket-granting service. This lack of interaction with the DC makes these methods extremely effective for maintaining stealthy, long-term persistent access.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.