Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 4Objective 1

Kerberos Attacks GPEN Practice Questions (Page 6)

Part of the Active Directory Attacks domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
12concepts

Questions 26–30

  1. 26application · medium

    Your domain was attacked using golden and silver tickets. You want to implement mitigations to reduce the impact of these attacks. Which measure is most effective?

    Select an answer first
  2. 27foundation · easy

    In the Kerberos authentication flow, which exchange occurs first when a user attempts to authenticate to a service?

    Select an answer first
  3. 28expert · hard

    You have write access to the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of a computer account. You want to gain access to that computer as a domain admin. Which attack should you perform?

    Select an answer first
  4. 29application · medium

    You are performing a password spraying attack against a domain. You have a list of valid usernames and a small list of common passwords. The domain account lockout threshold is set to 5 invalid attempts. Which strategy minimizes the risk of locking out accounts while still testing all passwords?

    Select an answer first
  5. 30foundation · easy

    What is the purpose of a Kerberos encryption type downgrade attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.