Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester needs to perform Kerberoasting against an Active Directory domain. Which step is required after requesting TGS tickets?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Crack the TGS hashes offline

After requesting TGS tickets for service accounts, the tester must crack the hashes offline using a tool like Hashcat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Crack the TGS hashes offline

    Why this is correct

    Kerberoasting correctly involves requesting service ticket (TGS) hashes for Service Principal Names (SPNs), then transferring them to an offline workstation. Because the TGS is encrypted with the target service account's NTLM hash, an attacker can run hashcat or John the Ripper against it to recover the plaintext password, especially if the password is weak or reused. The offline cracking step is what makes the attack low-risk and highly successful.

  • ✗

    Perform SMB relay

    Why it's wrong here

    SMB relay is a distinct network attack that intercepts and forwards SMB authentication exchanges to impersonate a victim or replay credentials, often to gain unauthorized access to a target system. It does not involve requesting or extracting Kerberos TGS tickets from a domain controller, and it typically relies on NTLM authentication rather than Kerberos. Kerberoasting, on the other hand, is entirely an offline kdc-issued ticket extraction and hash-cracking workflow.

  • ✗

    Request TGT ticket

    Why it's wrong here

    Requesting a TGT (Ticket-Granting Ticket) is the initial authentication phase where the KDC issues a ticket encrypted with the user's own password hash or session key after validating the user's credentials. This ticket is used to request TGS tickets but does not contain the service account's SPN hash, so it is useless for Kerberoasting. The attack specifically targets TGS responses, not TGTs, because only TGSs are encrypted with the target service account's key.

  • ✗

    Extract NTLM hashes from LSASS

    Why it's wrong here

    Extracting NTLM hashes from LSASS memory is a credential theft technique used for pass-the-hash or offline NTLM cracking, performed with tools like Mimikatz's sekurlsa::logonpasswords. This requires local administrative or SYSTEM privileges on the compromised host and directly dumps users' password hashes. Kerberoasting does not require local admin; it only needs a valid domain user account to request TGS tickets, and it exposes service account passwords rather than NTLM hashes of logged-in users.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.