PT0-002 Attacks and Exploits Practice Question
A penetration tester needs to perform Kerberoasting against an Active Directory domain. Which step is required after requesting TGS tickets?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Crack the TGS hashes offline
After requesting TGS tickets for service accounts, the tester must crack the hashes offline using a tool like Hashcat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Crack the TGS hashes offline
Why this is correct
Kerberoasting correctly involves requesting service ticket (TGS) hashes for Service Principal Names (SPNs), then transferring them to an offline workstation. Because the TGS is encrypted with the target service account's NTLM hash, an attacker can run hashcat or John the Ripper against it to recover the plaintext password, especially if the password is weak or reused. The offline cracking step is what makes the attack low-risk and highly successful.
- ✗
Perform SMB relay
Why it's wrong here
SMB relay is a distinct network attack that intercepts and forwards SMB authentication exchanges to impersonate a victim or replay credentials, often to gain unauthorized access to a target system. It does not involve requesting or extracting Kerberos TGS tickets from a domain controller, and it typically relies on NTLM authentication rather than Kerberos. Kerberoasting, on the other hand, is entirely an offline kdc-issued ticket extraction and hash-cracking workflow.
- ✗
Request TGT ticket
Why it's wrong here
Requesting a TGT (Ticket-Granting Ticket) is the initial authentication phase where the KDC issues a ticket encrypted with the user's own password hash or session key after validating the user's credentials. This ticket is used to request TGS tickets but does not contain the service account's SPN hash, so it is useless for Kerberoasting. The attack specifically targets TGS responses, not TGTs, because only TGSs are encrypted with the target service account's key.
- ✗
Extract NTLM hashes from LSASS
Why it's wrong here
Extracting NTLM hashes from LSASS memory is a credential theft technique used for pass-the-hash or offline NTLM cracking, performed with tools like Mimikatz's sekurlsa::logonpasswords. This requires local administrative or SYSTEM privileges on the compromised host and directly dumps users' password hashes. Kerberoasting does not require local admin; it only needs a valid domain user account to request TGS tickets, and it exposes service account passwords rather than NTLM hashes of logged-in users.
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
Kerberoasting
Kerberoasting is an attack where a hacker steals service account password hashes from Active Directory to crack them offline and gain unauthorized access.
Key term
Hashcat
Hashcat is a powerful password recovery tool that uses various attack methods to crack password hashes, widely used by security professionals and penetration testers.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.