Courseiva
Active Directory Attacks →hardMultiple Choice

PEN-200 Active Directory Attacks Practice Question

During a penetration test, you have gained access to a workstation and extracted a Kerberos TGT for a domain user. You want to use this ticket to access a file share on another server without knowing the user's password. Which technique should you employ?

⚠ Common exam trap

Test-takers frequently confuse Pass-the-Ticket with other Kerberos attacks like Overpass-the-Hash or Golden Ticket, which require different prerequisites such as hashes or elevated privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pass-the-Ticket by injecting the TGT into the current session using Mimikatz's kerberos::ptt command.

Pass-the-Ticket with Mimikatz's kerberos::ptt injects the stolen TGT into the current session, allowing Kerberos authentication as the user. This grants access to network resources such as file shares without needing the password. It is the appropriate technique when a TGT is already available and the goal is to use it for lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Silver Ticket by forging a service ticket for the file share using the service account's hash.

    Why it's wrong here

    A Silver Ticket is a forged service ticket that grants access to a specific service, but it requires the service account's NTLM hash. The scenario provides a TGT for a domain user, not a service account hash. While a Silver Ticket could grant access to the file share, it is not applicable here because you lack the necessary service hash and it is a different technique.

  • ✓

    Pass-the-Ticket by injecting the TGT into the current session using Mimikatz's kerberos::ptt command.

    Why this is correct

    Pass-the-Ticket with Mimikatz's kerberos::ptt injects the extracted TGT into the current logon session, allowing the attacker to impersonate the user for Kerberos authentication. This enables access to network resources like file shares without knowing the password. It is the standard method for leveraging stolen Kerberos tickets in Active Directory environments.

  • ✗

    Golden Ticket by forging a TGT using the KRBTGT hash to impersonate any user.

    Why it's wrong here

    A Golden Ticket requires the KRBTGT account's NTLM hash to forge a TGT, which is not available in this scenario. It provides domain-wide access but is a more advanced persistence technique. Since you already have a legitimate TGT for a user, using a Golden Ticket is unnecessary and not feasible without the KRBTGT hash.

  • ✗

    Overpass-the-Hash by using the TGT's associated NTLM hash to request a new TGT.

    Why it's wrong here

    Overpass-the-Hash involves using an NTLM hash to obtain a Kerberos TGT, typically via Mimikatz's sekurlsa::pth with the /kerberos flag. However, the scenario already provides a TGT, so this step is unnecessary. Overpass-the-Hash is used when you have a hash but no ticket; here, you already have the ticket, making this approach redundant and less direct.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.