
GIAC Penetration Tester (GPEN)
Domain 4Objective 1
Kerberos Attacks GPEN Practice Questions (Page 6)
Part of the Active Directory Attacks domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
12concepts
Questions 26–30
- 26
Your domain was attacked using golden and silver tickets. You want to implement mitigations to reduce the impact of these attacks. Which measure is most effective?
Select an answer first - 27
In the Kerberos authentication flow, which exchange occurs first when a user attempts to authenticate to a service?
Select an answer first - 28
You have write access to the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of a computer account. You want to gain access to that computer as a domain admin. Which attack should you perform?
Select an answer first - 29
You are performing a password spraying attack against a domain. You have a list of valid usernames and a small list of common passwords. The domain account lockout threshold is set to 5 invalid attempts. Which strategy minimizes the risk of locking out accounts while still testing all passwords?
Select an answer first - 30
What is the purpose of a Kerberos encryption type downgrade attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.