PT0-002 Attacks and Exploits Practice Question
During an internal assessment, a penetration tester captures Kerberos traffic and identifies a service account whose SPN is registered but whose password was set years ago and never rotated. The tester wants to request a service ticket offline and crack it to recover the plaintext password. Which technique is the tester performing?
⚠ Common exam trap
Watch out — candidates often confuse offline service-ticket cracking with AS-REP roasting, which instead depends on accounts that have Kerberos pre-authentication disabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kerberoasting, by requesting a TGS for the SPN and cracking the RC4-HMAC encrypted portion offline
Kerberoasting exploits the fact that any authenticated user may request a service ticket for a registered SPN, and the returned TGS is encrypted with the service account's key. Extracting and cracking that encrypted blob offline yields the plaintext password. The long-lived, unrotated password in the scenario is the classic enabling condition, making this the correct identification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Kerberoasting, by requesting a TGS for the SPN and cracking the RC4-HMAC encrypted portion offline
Why this is correct
Kerberoasting requests a service ticket (TGS) for a registered SPN using any authenticated domain user. The ticket's encrypted portion is protected with the service account's long-term key, so the tester can extract it and crack it offline to recover the plaintext password. The stale, never-rotated password described in the scenario is exactly the condition that makes this attack productive.
- ✗
AS-REP roasting, by sending an AS-REQ without pre-authentication for a targeted account
Why it's wrong here
AS-REP roasting targets accounts configured with 'Do not require Kerberos preauthentication'. It abuses the AS-REP response, not a service ticket. The scenario describes a service account with a registered SPN and a stale password, which points to a TGS-based attack rather than the pre-auth-disabled condition that AS-REP roasting depends on.
- ✗
Golden Ticket creation, by forging a TGT with the KRBTGT account hash
Why it's wrong here
A Golden Ticket is forged offline using the KRBTGT account's NTLM hash to mint arbitrary TGTs, granting broad domain persistence. That requires prior compromise of the KRBTGT hash, typically from a domain controller. The scenario only involves a single service account's registered SPN, so forging domain-wide tickets is not the technique being performed.
- ✗
Pass-the-ticket, by injecting a stolen TGS into the current session for lateral movement
Why it's wrong here
Pass-the-ticket reuses a valid, already-obtained Kerberos ticket to authenticate elsewhere without knowing the password. It moves laterally but does not recover any plaintext credential. The scenario's goal is to crack the ticket offline to obtain the service account password, which pass-the-ticket does not accomplish because it never decrypts the ticket.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.