Courseiva

PT0-002 Post-exploitation and Lateral Movement Practice Question

A penetration tester has gained access to a Windows domain controller and wants to extract Kerberos tickets from memory to perform a pass-the-ticket attack. Which tool and command should the tester use to list and export all Kerberos tickets from the current session?

⚠ Common exam trap

Watch out — candidates often confuse pass-the-ticket with golden ticket creation, leading to the selection of commands that forge tickets rather than export existing ones.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

mimikatz # sekurlsa::tickets /export

To perform pass-the-ticket, the tester needs to extract Kerberos tickets from memory. Mimikatz's sekurlsa::tickets module lists all tickets in the current session and can export them with /export. The exported .kirbi files can then be injected using kerberos::ptt. Other commands like kerberos::golden forge new tickets, lsadump::dcsync retrieves the KRBTGT hash, and sekurlsa::logonpasswords extracts passwords but not tickets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    mimikatz # sekurlsa::tickets /export

    Why this is correct

    The sekurlsa::tickets command in Mimikatz lists all Kerberos tickets in memory for the current session, and the /export option exports them to .kirbi files. These files can then be used with kerberos::ptt to inject the tickets into a new session, enabling pass-the-ticket. This is the standard method for extracting and reusing Kerberos tickets during post-exploitation.

  • ✗

    mimikatz # lsadump::dcsync /user:krbtgt

    Why it's wrong here

    This command performs a DCSync attack to replicate the KRBTGT account password hash from the domain controller. It is used to obtain the KRBTGT hash for forging golden tickets, not to extract existing Kerberos tickets from memory. DCSync requires domain administrator or replication privileges and does not directly provide tickets for pass-the-ticket; it provides the material to create new tickets.

  • ✗

    mimikatz # sekurlsa::logonpasswords

    Why it's wrong here

    This command extracts plaintext passwords, hashes, and PINs from memory for logged-on users. While it can reveal credentials, it does not list or export Kerberos tickets. Pass-the-ticket specifically requires the ticket-granting ticket (TGT) or service tickets, which this command does not provide. Therefore, it is not the correct tool for extracting Kerberos tickets for a pass-the-ticket attack.

  • ✗

    mimikatz # kerberos::golden /user:Administrator /domain:example.com /sid:S-1-5-21-... /krbtgt:... /ticket:golden.kirbi

    Why it's wrong here

    This command forges a golden ticket using the KRBTGT account hash, which is a persistence technique that requires the KRBTGT hash. It does not list or export existing tickets from memory. The scenario asks for extracting current tickets, not forging new ones. Golden tickets are powerful but are not the same as pass-the-ticket, which reuses legitimate tickets already present in memory.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.