A city service account has SPNs registered and is exempt from the strong password policy. Which risk class should the tester highlight?
Select an answer to reveal the explanation.
Short Explanation
SPNs say 'this account runs a service,' and a weak password says 'please guess me.' Together they are a classic Kerberoast-shaped problem — no recipe required to know that combo is trouble.
Full Explanation
Accounts with Service Principal Names are associated with Kerberos service ticket requests. When those accounts also have weak or exempted passwords, they represent a recognized credential-exposure class commonly discussed as Kerberoasting-related risk. Membership outside Domain Admin does not remove that theme, and SPNs are not limited to printer discovery. Reporting the misconfiguration class helps clients prioritize password and service-account hygiene.