PT0-002 Post-exploitation and Lateral Movement Practice Question
A penetration tester has gained access to a Windows domain controller and wants to extract Kerberos tickets from memory to perform a pass-the-ticket attack. Which tool and command should the tester use to list and export all Kerberos tickets from the current session?
⚠ Common exam trap
Watch out — candidates often confuse pass-the-ticket with golden ticket creation, leading to the selection of commands that forge tickets rather than export existing ones.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
mimikatz # sekurlsa::tickets /export
To perform pass-the-ticket, the tester needs to extract Kerberos tickets from memory. Mimikatz's sekurlsa::tickets module lists all tickets in the current session and can export them with /export. The exported .kirbi files can then be injected using kerberos::ptt. Other commands like kerberos::golden forge new tickets, lsadump::dcsync retrieves the KRBTGT hash, and sekurlsa::logonpasswords extracts passwords but not tickets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
mimikatz # sekurlsa::tickets /export
Why this is correct
The sekurlsa::tickets command in Mimikatz lists all Kerberos tickets in memory for the current session, and the /export option exports them to .kirbi files. These files can then be used with kerberos::ptt to inject the tickets into a new session, enabling pass-the-ticket. This is the standard method for extracting and reusing Kerberos tickets during post-exploitation.
- ✗
mimikatz # lsadump::dcsync /user:krbtgt
Why it's wrong here
This command performs a DCSync attack to replicate the KRBTGT account password hash from the domain controller. It is used to obtain the KRBTGT hash for forging golden tickets, not to extract existing Kerberos tickets from memory. DCSync requires domain administrator or replication privileges and does not directly provide tickets for pass-the-ticket; it provides the material to create new tickets.
- ✗
mimikatz # sekurlsa::logonpasswords
Why it's wrong here
This command extracts plaintext passwords, hashes, and PINs from memory for logged-on users. While it can reveal credentials, it does not list or export Kerberos tickets. Pass-the-ticket specifically requires the ticket-granting ticket (TGT) or service tickets, which this command does not provide. Therefore, it is not the correct tool for extracting Kerberos tickets for a pass-the-ticket attack.
- ✗
mimikatz # kerberos::golden /user:Administrator /domain:example.com /sid:S-1-5-21-... /krbtgt:... /ticket:golden.kirbi
Why it's wrong here
This command forges a golden ticket using the KRBTGT account hash, which is a persistence technique that requires the KRBTGT hash. It does not list or export existing tickets from memory. The scenario asks for extracting current tickets, not forging new ones. Golden tickets are powerful but are not the same as pass-the-ticket, which reuses legitimate tickets already present in memory.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.