Kerberos
The ticket-based network authentication protocol tested in CISSP Domain 5: a trusted KDC issues a TGT, then service tickets, using symmetric encryption so passwords never cross the wire.
Full guide: Kerberos: The Six-Step Ticket Flow Explained
Kerberos is the ticket-based authentication protocol defined in RFC 4120 and used as the default authentication protocol in Windows Active Directory domains. The moving parts a candidate is expected to know: the Key Distribution Center (KDC) with its Authentication Service and Ticket Granting Service, the Ticket Granting Ticket (TGT) you receive at logon, and the service tickets you present to each server you access.
What matters here is the properties, not the packet layout. Kerberos uses symmetric encryption, provides mutual authentication (client and server verify each other), and never sends the password across the network. Its classic weak points matter as much: the KDC is a single point of failure, and the whole protocol depends on loosely synchronised clocks because tickets carry timestamps to resist replay attacks.
Exam relevance: a scenario that mentions tickets, a KDC, or mutual authentication in a Windows domain is likely to be describing Kerberos, and candidates are expected to connect its attack chain (golden ticket, silver ticket, Kerberoasting) back to the protocol properties above.