PT0-002 Attacks and Exploits Practice Question
During a penetration test, the tester gains access to a domain-joined Windows machine and wants to perform Kerberoasting. Which THREE conditions are necessary for a successful Kerberoasting attack?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ability to request TGS-REP tickets
The user must have domain credentials, there must be service accounts with SPNs, and the attacker must be able to request TGS tickets. Plaintext passwords are not required, and local admin is not needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Local administrator privileges on the target
Why it's wrong here
Kerberoasting does not require local administrator privileges on any target host. The attack is performed entirely from an authenticated domain user context over the network, requesting service tickets via the Kerberos protocol and then cracking them offline. Local admin would be needed for other post-exploitation techniques like DCSync or credential dumping, but it is not a precondition for Kerberoasting.
- ✓
Ability to request TGS-REP tickets
Why this is correct
This is the core action in Kerberoasting: the attacker must be able to send a TGS-REQ for a target SPN and receive the corresponding TGS-REP ticket. The returned service ticket is encrypted with a key derived from the service account's password hash, so possessing that ticket enables offline brute-force or dictionary attacks to recover the plaintext password.
- ✓
Valid domain user credentials
Why this is correct
A valid domain user account is the fundamental prerequisite because Kerberoasting requires the ability to authenticate to Kerberos and request service tickets. Any authenticated domain user, regardless of privileges, can request TGS tickets for any SPN registered in Active Directory, so an unprivileged account is sufficient to initiate the attack.
- ✗
Plaintext password of the service account
Why it's wrong here
If the tester already possessed the plaintext password of the target service account, Kerberoasting would be unnecessary because the goal is to crack the password from the TGS ticket. The attack specifically exploits the fact that the ticket exposes a password-derived encryption key to offline cracking; having the password in advance defeats the purpose and is not required to perform the attack.
- ✓
Service accounts with SPNs registered
Why this is correct
The attacker needs at least one service account that has a Service Principal Name (SPN) registered in Active Directory. When requesting a TGS ticket for that SPN, the ticket is encrypted with the service account's password-derived key; without an SPN-protected service account, there is no ticket to request and nothing to crack offline.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.