
GIAC Penetration Tester (GPEN)
Domain 4Objective 1
Kerberos Attacks GPEN Practice Questions (Page 7)
Part of the Active Directory Attacks domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
12concepts
Questions 31–35
- 31
You are performing Kerberoasting in an environment where the domain controller has AES enabled, but you want to maximize the speed of offline cracking. You have the ability to modify the encryption types supported by your test client. Which encryption type should you request for the service ticket?
Select an answer first - 32
What is the key difference between a Golden Ticket and a Silver Ticket attack?
Select an answer first - 33
Your organization wants to mitigate Kerberoasting, AS-REP roasting, and downgrade attacks. You have a mix of legacy and modern systems. Which set of mitigations provides the best balance of security and compatibility?
Select an answer first - 34
What is the primary tool used to crack Kerberos tickets offline?
Select an answer first - 35
You are troubleshooting a user's inability to access a network share. The user can authenticate to the domain but receives an access denied error when accessing the share. You suspect a Kerberos issue. Which exchange is most likely failing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.