Courseiva
Active Directory Attacks →mediumMultiple Choice

PEN-200 Active Directory Attacks Practice Question

During an internal assessment you compromise a workstation and recover a Kerberos TGS ticket from memory that belongs to a service account. Analysis shows the ticket was encrypted with the RC4-HMAC cipher using a key derived from the service account's password hash. You want to recover the plaintext password of that service account offline. Which action should you take?

⚠ Common exam trap

The trap here is assuming a captured service ticket can be replayed to the KDC to reveal the password, when in fact Kerberoasting success depends on cracking the RC4-encrypted ticket offline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Crack the ticket offline with Hashcat in mode 13100, since the ticket is encrypted with RC4-HMAC and its checksum can be attacked with a wordlist.

A service ticket encrypted with RC4-HMAC (etype 23) is protected by a key derived from the target service account's NT hash, so the ciphertext can be attacked entirely offline. Extracting the TGS-REP hash and running Hashcat mode 13100 against a wordlist recovers the plaintext password when it is weak, without generating additional authentication traffic against the domain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Submit the ticket to the domain controller with GetUserSPNs.py and let the KDC decrypt it to disclose the service account's NT hash.

    Why it's wrong here

    GetUserSPNs.py requests new service tickets for accounts with SPNs so they can be cracked offline; it does not submit an existing ticket for decryption. The KDC has no interface that returns an account's NT hash to a requester, so this approach cannot produce the credential.

  • ✗

    Convert the ticket to a .kirbi file and import it with Rubeus to request a service ticket that reveals the account password in the response.

    Why it's wrong here

    Importing a .kirbi with Rubeus supports pass-the-ticket, letting you reuse the existing service access, but the KDC never returns a password in any ticket response. No Kerberos message contains the plaintext password, so this path cannot yield the credential you are trying to recover.

  • ✗

    Use Kerbrute to spray the recovered ticket against the domain controller and read the resulting authentication error codes.

    Why it's wrong here

    Kerbrute performs online username enumeration and password spraying against Kerberos pre-authentication; it does not take a captured TGS ticket as input and cannot derive a password from ciphertext. Running it here would generate failed logon events and lockout risk without recovering the service account password from the ticket.

  • ✓

    Crack the ticket offline with Hashcat in mode 13100, since the ticket is encrypted with RC4-HMAC and its checksum can be attacked with a wordlist.

    Why this is correct

    A TGS-REP ticket encrypted with RC4-HMAC can be brute-forced offline because the checksum is keyed by the service account's NT hash. Hashcat mode 13100 targets Kerberos 5 TGS-REP etype 23 hashes exactly, allowing a wordlist or rule-based attack to recover the plaintext, which is the standard Kerberoasting cracking path.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.