PEN-200 Active Directory Attacks Practice Question
During an internal assessment you compromise a workstation and recover a Kerberos TGS ticket from memory that belongs to a service account. Analysis shows the ticket was encrypted with the RC4-HMAC cipher using a key derived from the service account's password hash. You want to recover the plaintext password of that service account offline. Which action should you take?
⚠ Common exam trap
The trap here is assuming a captured service ticket can be replayed to the KDC to reveal the password, when in fact Kerberoasting success depends on cracking the RC4-encrypted ticket offline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Crack the ticket offline with Hashcat in mode 13100, since the ticket is encrypted with RC4-HMAC and its checksum can be attacked with a wordlist.
A service ticket encrypted with RC4-HMAC (etype 23) is protected by a key derived from the target service account's NT hash, so the ciphertext can be attacked entirely offline. Extracting the TGS-REP hash and running Hashcat mode 13100 against a wordlist recovers the plaintext password when it is weak, without generating additional authentication traffic against the domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Submit the ticket to the domain controller with GetUserSPNs.py and let the KDC decrypt it to disclose the service account's NT hash.
Why it's wrong here
GetUserSPNs.py requests new service tickets for accounts with SPNs so they can be cracked offline; it does not submit an existing ticket for decryption. The KDC has no interface that returns an account's NT hash to a requester, so this approach cannot produce the credential.
- ✗
Convert the ticket to a .kirbi file and import it with Rubeus to request a service ticket that reveals the account password in the response.
Why it's wrong here
Importing a .kirbi with Rubeus supports pass-the-ticket, letting you reuse the existing service access, but the KDC never returns a password in any ticket response. No Kerberos message contains the plaintext password, so this path cannot yield the credential you are trying to recover.
- ✗
Use Kerbrute to spray the recovered ticket against the domain controller and read the resulting authentication error codes.
Why it's wrong here
Kerbrute performs online username enumeration and password spraying against Kerberos pre-authentication; it does not take a captured TGS ticket as input and cannot derive a password from ciphertext. Running it here would generate failed logon events and lockout risk without recovering the service account password from the ticket.
- ✓
Crack the ticket offline with Hashcat in mode 13100, since the ticket is encrypted with RC4-HMAC and its checksum can be attacked with a wordlist.
Why this is correct
A TGS-REP ticket encrypted with RC4-HMAC can be brute-forced offline because the checksum is keyed by the service account's NT hash. Hashcat mode 13100 targets Kerberos 5 TGS-REP etype 23 hashes exactly, allowing a wordlist or rule-based attack to recover the plaintext, which is the standard Kerberoasting cracking path.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.