Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During an internal assessment, a penetration tester captures Kerberos traffic and identifies a service account whose SPN is registered but whose password was set years ago and never rotated. The tester wants to request a service ticket offline and crack it to recover the plaintext password. Which technique is the tester performing?

⚠ Common exam trap

Watch out — candidates often confuse offline service-ticket cracking with AS-REP roasting, which instead depends on accounts that have Kerberos pre-authentication disabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kerberoasting, by requesting a TGS for the SPN and cracking the RC4-HMAC encrypted portion offline

Kerberoasting exploits the fact that any authenticated user may request a service ticket for a registered SPN, and the returned TGS is encrypted with the service account's key. Extracting and cracking that encrypted blob offline yields the plaintext password. The long-lived, unrotated password in the scenario is the classic enabling condition, making this the correct identification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Kerberoasting, by requesting a TGS for the SPN and cracking the RC4-HMAC encrypted portion offline

    Why this is correct

    Kerberoasting requests a service ticket (TGS) for a registered SPN using any authenticated domain user. The ticket's encrypted portion is protected with the service account's long-term key, so the tester can extract it and crack it offline to recover the plaintext password. The stale, never-rotated password described in the scenario is exactly the condition that makes this attack productive.

  • ✗

    AS-REP roasting, by sending an AS-REQ without pre-authentication for a targeted account

    Why it's wrong here

    AS-REP roasting targets accounts configured with 'Do not require Kerberos preauthentication'. It abuses the AS-REP response, not a service ticket. The scenario describes a service account with a registered SPN and a stale password, which points to a TGS-based attack rather than the pre-auth-disabled condition that AS-REP roasting depends on.

  • ✗

    Golden Ticket creation, by forging a TGT with the KRBTGT account hash

    Why it's wrong here

    A Golden Ticket is forged offline using the KRBTGT account's NTLM hash to mint arbitrary TGTs, granting broad domain persistence. That requires prior compromise of the KRBTGT hash, typically from a domain controller. The scenario only involves a single service account's registered SPN, so forging domain-wide tickets is not the technique being performed.

  • ✗

    Pass-the-ticket, by injecting a stolen TGS into the current session for lateral movement

    Why it's wrong here

    Pass-the-ticket reuses a valid, already-obtained Kerberos ticket to authenticate elsewhere without knowing the password. It moves laterally but does not recover any plaintext credential. The scenario's goal is to crack the ticket offline to obtain the service account password, which pass-the-ticket does not accomplish because it never decrypts the ticket.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.