Courseiva
Attacks and Exploits →hardMultiple Select

PT0-002 Attacks and Exploits Practice Question

During a penetration test, the tester gains access to a domain-joined Windows machine and wants to perform Kerberoasting. Which THREE conditions are necessary for a successful Kerberoasting attack?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ability to request TGS-REP tickets

The user must have domain credentials, there must be service accounts with SPNs, and the attacker must be able to request TGS tickets. Plaintext passwords are not required, and local admin is not needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Local administrator privileges on the target

    Why it's wrong here

    Kerberoasting does not require local administrator privileges on any target host. The attack is performed entirely from an authenticated domain user context over the network, requesting service tickets via the Kerberos protocol and then cracking them offline. Local admin would be needed for other post-exploitation techniques like DCSync or credential dumping, but it is not a precondition for Kerberoasting.

  • ✓

    Ability to request TGS-REP tickets

    Why this is correct

    This is the core action in Kerberoasting: the attacker must be able to send a TGS-REQ for a target SPN and receive the corresponding TGS-REP ticket. The returned service ticket is encrypted with a key derived from the service account's password hash, so possessing that ticket enables offline brute-force or dictionary attacks to recover the plaintext password.

  • ✓

    Valid domain user credentials

    Why this is correct

    A valid domain user account is the fundamental prerequisite because Kerberoasting requires the ability to authenticate to Kerberos and request service tickets. Any authenticated domain user, regardless of privileges, can request TGS tickets for any SPN registered in Active Directory, so an unprivileged account is sufficient to initiate the attack.

  • ✗

    Plaintext password of the service account

    Why it's wrong here

    If the tester already possessed the plaintext password of the target service account, Kerberoasting would be unnecessary because the goal is to crack the password from the TGS ticket. The attack specifically exploits the fact that the ticket exposes a password-derived encryption key to offline cracking; having the password in advance defeats the purpose and is not required to perform the attack.

  • ✓

    Service accounts with SPNs registered

    Why this is correct

    The attacker needs at least one service account that has a Service Principal Name (SPN) registered in Active Directory. When requesting a TGS ticket for that SPN, the ticket is encrypted with the service account's password-derived key; without an SPN-protected service account, there is no ticket to request and nothing to crack offline.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.