← Back to Kerberos Authentication Fundamentals

Kerberos Authentication Fundamentals Quiz

7 questions


1.What does "stateless" mean in the context of Kerberos authentication?

2.How does a Ticket Granting Ticket (TGT) differ from a service ticket in scope?

3.Why doesn't a user's password cross the network during Kerberos authentication?

4.A colleague says Kerberos maintains a persistent, VPN-like connection between a client and the KDC once a user logs in. What is the flaw in that claim?

5.Why does clock accuracy matter so much for Kerberos, given that passwords never cross the network?

6.A junior analyst assumes a fresh TGT gets requested for every single action a user takes throughout the day. What is wrong with that assumption?

7.In the claim-check mental model, why doesn't the KDC need to recognize a user's face or recall serving them minutes earlier?