PT0-002 Attacks and Exploits Practice Question
A tester is performing a Kerberoasting attack. After requesting TGS tickets for accounts with SPNs, what is the next step to obtain plaintext credentials?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Crack the TGS tickets using Hashcat or John the Ripper
Kerberoasting involves cracking the TGS tickets offline to recover the service account password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pass-the-ticket to access services
Why it's wrong here
Pass-the-ticket is a lateral movement technique that reuses a captured Kerberos TGT or service ticket from memory, but it does not require cracking anything. The attacker simply injects the valid ticket into their session with Mimikatz or Rubeus to impersonate the user. This approach bypasses the offline brute-force step of Kerberoasting, so it is not the intended next action after requesting TGS tickets for offline cracking.
- ✗
Relay the TGS tickets to another server
Why it's wrong here
Relaying Kerberos tickets is not a valid attack because Kerberos tickets are not relayed like NTLM authentication. Relay attacks, such as SMB relay, operate on NTLM challenge-response authentication, where a captured hash can be forwarded to another server. TGS tickets are session tickets encrypted with the service account's key and tied to the target SPN, so they cannot be replayed to a different service or host in the same way.
- ✗
Use the TGS tickets for silver ticket attacks
Why it's wrong here
Silver tickets are forged Kerberos TGTs or TGSs generated by an attacker who has obtained the NTLM hash of the target service account. Kerberoasting provides the hash through cracking the TGS, but the TGS itself is not a forged ticket. Crafting a silver ticket requires the already-cracked service account hash, making it a subsequent attack step, not a use of the crackable TGS ticket directly.
- ✓
Crack the TGS tickets using Hashcat or John the Ripper
Why this is correct
Kerberoasting involves requesting TGS tickets for service accounts via SPN, then extracting the tickets and cracking them offline with Hashcat or John the Ripper. The TGS is encrypted with the service account's NTLM hash, and because many service accounts have weak or human-memorizable passwords, the encrypted blob can be brute-forced or dictionary-attacked offline. Successful cracking yields the service account's plaintext password, enabling further compromise.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.