Courseiva
Attacks and Exploits →mediumMultiple Select

PT0-002 Attacks and Exploits Practice Question

A penetration tester is performing a Kerberoasting attack. Which TWO steps are required for a successful Kerberoasting attack?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request TGS tickets for service accounts

Kerberoasting involves requesting TGS tickets for service accounts and then cracking the tickets offline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enumerate domain admins

    Why it's wrong here

    Enumerating Domain Admins is not a required step in Kerberoasting; the attack targets accounts with Service Principal Names (SPNs) regardless of group membership. While identifying Domain Admins could help prioritize which TGS tickets to crack, the actual Kerberoasting workflow only requires discovering SPN-linked accounts and requesting their tickets. Spending time on admin enumeration adds noise and may trigger detections without advancing the ticket extraction.

  • ✓

    Request TGS tickets for service accounts

    Why this is correct

    Kerberoasting begins with an authenticated user requesting TGS tickets for accounts that have SPNs registered, typically via tools like Rubeus or GetUserSPNs. The returned ticket is encrypted with the target service account's NTLM hash, so capturing these tickets yields a hash that can be cracked offline without any further network interaction. This step is the core of the attack because it obtains the password hash in an extractable format, and it works with only standard domain credentials.

  • ✗

    Perform a relay attack

    Why it's wrong here

    Performing a relay attack is unrelated to Kerberoasting; NTLM relay captures authentication messages (e.g., SMB, HTTP) and forwards them to a target server to authenticate or execute commands. Kerberoasting instead pulls Kerberos TGS tickets encrypted with a service account's NTLM hash and cracks them offline. Relaying requires an active network position and targeted service, whereas Kerberoasting works with a single set of valid credentials and no further network interaction.

  • ✓

    Crack the TGS tickets offline using Hashcat

    Why this is correct

    Once TGS tickets are extracted, cracking them offline with Hashcat is the concluding step; Hashcat mode 13100 is specifically designed for Kerberos 5 TGS-REP etype 23 hashes. This step converts the encrypted ticket data into a crackable format, and because the ticket is encrypted with the service account's NTLM hash, a successful crack reveals the plaintext password. It is a legitimate phase of Kerberoasting, though it requires the tickets already obtained in the request step.

  • ✗

    Capture NTLMv2 hashes using Responder

    Why it's wrong here

    Capturing NTLMv2 hashes with Responder is a different attack vector; Responder poisons LLMNR/NBT-NS to intercept network authentication attempts and collects NTLMv2 challenge-response hashes. Kerberoasting does not rely on network poisoning or challenge-response; it extracts Kerberos TGS tickets that are encrypted with the service account's NTLM hash. These hash types require separate cracking modes, and Responder's output cannot be directly substituted for TGS tickets in a Kerberoasting workflow.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.