CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

During a red team engagement, testers who compromised a domain controller extract the krbtgt account's password hash and use it to forge Kerberos ticket-granting tickets, granting themselves domain admin access that persists even after the original compromised account's password is reset. Which attack was performed?

  1. ASilver ticket attack
  2. BGolden ticket attack
  3. CPass-the-hash attack
  4. DKerberoasting
Show answer & explanation

Correct answer: B. Golden ticket attack

A golden ticket attack uses the compromised krbtgt account hash to forge arbitrary Kerberos TGTs, granting long-term, persistent domain-wide access regardless of subsequent password changes to individual user accounts.

Why the other options are wrong

  • A. A silver ticket forges a service ticket (TGS) for a specific service using that service's hash, not the krbtgt hash for domain-wide access.
  • C. Pass-the-hash reuses a captured NTLM hash to authenticate directly, not forge Kerberos tickets.
  • D. Kerberoasting cracks service ticket hashes offline rather than forging tickets with the krbtgt hash.

Golden Ticket Attack

An attack that uses the krbtgt account's password hash to forge Kerberos TGTs, granting attackers persistent, domain-wide access.

  • Requires krbtgt hash compromise, typically from a domain controller
  • Grants access even after user password resets
  • Mitigated by resetting krbtgt password (twice) and monitoring ticket lifetimes

Memory trick: The golden ticket is the master key that opens every domain door forever.

More Threats, Vulnerabilities, and Mitigations questions