Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 4Objective 1

Kerberos Attacks GPEN Practice Questions (Page 9)

Part of the Active Directory Attacks domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 6–9 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
12concepts

Questions 41–45

  1. 41application · medium

    You are analyzing a captured Kerberos service ticket. You want to determine which account's password hash was used to encrypt the ticket. Which component of the ticket should you examine?

    Select an answer first
  2. 42foundation · easy

    What monitoring activity can help detect a Golden Ticket attack?

    Select an answer first
  3. 43foundation · easy

    Which mitigation is most effective against Kerberoasting attacks?

    Select an answer first
  4. 44foundation · easy

    What does an attacker obtain in an AS-REP Roasting attack?

    Select an answer first
  5. 45application · medium

    A penetration tester has domain credentials for a standard user account and needs to obtain a crackable hash for a service account that runs a custom web application. The service account has an SPN registered. The tester wants to avoid any interaction with the domain controller beyond normal Kerberos requests. Which technique should the tester use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GPEN

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.