Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester needs to perform a Kerberoasting attack against a Windows Active Directory environment. Which tool from the Impacket suite should the tester use to request service tickets and extract TGS hashes for offline cracking?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GetUserSPNs.py

GetUserSPNs.py in the Impacket suite is used to find and request service principal names (SPNs) and retrieve TGS hashes for Kerberoasting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    wmiexec.py

    Why it's wrong here

    wmiexec.py (from Impacket) is designed to execute commands remotely over Windows Management Instrumentation (WMI) using valid credentials, typically for interactive lateral movement or command-and-control. It does not request Kerberos service tickets for service principal names (SPNs), which is the core mechanism of a Kerberoasting attack. While WMI may incidentally trigger Kerberos authentication, wmiexec.py's operational purpose is remote execution, not harvesting TGS tickets for offline password cracking.

  • ✗

    secretsdump.py

    Why it's wrong here

    secretsdump.py (from Impacket) extracts credential material that is already stored on disk, such as password hashes from the SAM registry hive, NTDS.dit database, or cached domain credentials via LSA secrets. This tool targets post-exploitation credential dumping, often from a compromised domain controller, whereas Kerberoasting obtains a TGS ticket by interacting with the Ticket Granting Service over the network as an ordinary authenticated user. The two techniques operate at different stages: secretsdump.py reads stored secrets, while Kerberoasting leverages the Kerberos protocol to obtain crackable encrypted material tied to an SPN.

  • ✓

    GetUserSPNs.py

    Why this is correct

    GetUserSPNs.py (from Impacket) is the correct choice because it specifically enumerates user accounts registered as Service Principal Names (SPNs) and requests Kerberos service tickets for those SPNs, which are encrypted with the target user account's password-derived key. It outputs a John-the-Ripper/hashcat-ready hash that can be cracked offline to recover the plaintext password. This tool automates the full Kerberoasting workflow—querying for SPNs, requesting TGS tickets, and formatting the output—making it the canonical tool for this attack.

  • ✗

    psexec.py

    Why it's wrong here

    psexec.py (from Impacket) is designed for remote command execution by creating a Windows service on the target system via the SMB protocol, typically requiring administrative credentials. Its focus is on interactive lateral movement and service control, not on querying the domain for SPNs or requesting TGS tickets. Unlike Kerberoasting, which can be performed by any standard domain user and targets Kerberos ticket encryption, psexec.py operates through SMB file shares and service management and does not produce a crackable Kerberos ticket.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.