Courseiva
hardMultiple Choice

How to Detect and Triage Kerberoasting Attacks

A SIEM alert shows one workstation requesting a high number of Kerberos service tickets for many SPNs, followed by no corresponding service access. Which attack should be suspected?

⚠ Common exam trap

The CS0-004 exam often tests the distinction between reconnaissance (ticket harvesting without access) and actual exploitation; the trap here is confusing Kerberoasting with pass-the-ticket or golden ticket attacks, which involve ticket reuse or forgery rather than offline hash cracking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kerberoasting reconnaissance or ticket harvesting

A high volume of Kerberos service ticket requests for many SPNs, followed by no actual service access, is characteristic of Kerberoasting reconnaissance. In this attack, an adversary with valid domain credentials requests TGS tickets for service accounts to extract the NTLM hash embedded in the ticket, which can then be cracked offline. The lack of subsequent service access confirms the tickets were obtained solely for offline brute-force cracking, not legitimate use.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Kerberoasting reconnaissance or ticket harvesting

    Why this is correct

    Kerberoasting involves an attacker requesting service tickets (TGS-REQs) for various Service Principal Names (SPNs) registered in Active Directory. These tickets contain a hash of the service account's password, encrypted with the service account's NTLM hash. A high volume of TGS-REQ requests from a single workstation, especially for numerous different service principals, is a strong indicator of an attacker attempting to harvest these tickets offline for brute-forcing the password hashes to gain credentials.

  • ✗

    DNS cache poisoning

    Why it's wrong here

    DNS cache poisoning involves injecting corrupted Domain Name System (DNS) data into a DNS resolver's cache, causing the resolver to return an incorrect IP address for a legitimate domain name. This redirects users to malicious websites or services. While a serious threat, DNS cache poisoning primarily manipulates name resolution at the application layer and does not directly manifest as an increased volume of Kerberos Service Ticket Granting Service (TGS) requests, which are specific to Active Directory authentication.

  • ✗

    Pass-the-hash using NTLM only

    Why it's wrong here

    Pass-the-hash (PtH) is an attack technique where an attacker authenticates to a remote server or service by using a user's NTLM password hash instead of the plaintext password. While effective for NTLM-based authentication, this attack does not involve the generation or high volume of Kerberos Service Ticket Granting Service (TGS) requests. The observed pattern of numerous TGS-REQs specifically points to Kerberos-related activity, not NTLM hash reuse.

  • ✗

    ARP spoofing

    Why it's wrong here

    ARP spoofing operates at Layer 2 (Data Link Layer) by sending forged Address Resolution Protocol (ARP) messages to link an attacker's MAC address with the IP address of a legitimate network device. This allows the attacker to intercept, modify, or stop traffic. However, this attack manipulates local network address resolution and does not directly generate or explain a high volume of Kerberos service ticket (TGS-REQ) requests from a workstation, which is an application-layer authentication protocol activity.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.