PT0-002 · Question #554
A penetration tester obtains the hash of a service account within a customer's Active Directory. Which of the following attacks should the penetration tester attempt next?
The correct answer is D. Kerberoasting. Kerberoasting is an attack technique that targets Active Directory environments. If the penetration tester has obtained the hash of a service account, they can attempt a Kerberoasting attack to crack the hash and potentially retrieve the service account's plaintext password…
Question
A penetration tester obtains the hash of a service account within a customer's Active Directory. Which of the following attacks should the penetration tester attempt next?
Options
- APassword spraying
- BGolden ticket
- CCache poisoning
- DKerberoasting
How the community answered
(54 responses)- A7% (4)
- B17% (9)
- C4% (2)
- D72% (39)
Explanation
Kerberoasting is an attack technique that targets Active Directory environments. If the penetration tester has obtained the hash of a service account, they can attempt a Kerberoasting attack to crack the hash and potentially retrieve the service account's plaintext password. Kerberoasting leverages the fact that service accounts often have SPNs (Service Principal Names) registered in Active Directory. These accounts typically use weaker passwords and are susceptible to offline password cracking once their ticket-granting service (TGS) tickets are
Topics
Community Discussion
No community discussion yet for this question.