nerdexam
CompTIA

PT0-002 · Question #554

A penetration tester obtains the hash of a service account within a customer's Active Directory. Which of the following attacks should the penetration tester attempt next?

The correct answer is D. Kerberoasting. Kerberoasting is an attack technique that targets Active Directory environments. If the penetration tester has obtained the hash of a service account, they can attempt a Kerberoasting attack to crack the hash and potentially retrieve the service account's plaintext password…

Attacks and Exploits

Question

A penetration tester obtains the hash of a service account within a customer's Active Directory. Which of the following attacks should the penetration tester attempt next?

Options

  • APassword spraying
  • BGolden ticket
  • CCache poisoning
  • DKerberoasting

How the community answered

(54 responses)
  • A
    7% (4)
  • B
    17% (9)
  • C
    4% (2)
  • D
    72% (39)

Explanation

Kerberoasting is an attack technique that targets Active Directory environments. If the penetration tester has obtained the hash of a service account, they can attempt a Kerberoasting attack to crack the hash and potentially retrieve the service account's plaintext password. Kerberoasting leverages the fact that service accounts often have SPNs (Service Principal Names) registered in Active Directory. These accounts typically use weaker passwords and are susceptible to offline password cracking once their ticket-granting service (TGS) tickets are

Topics

#Active Directory#Kerberoasting#Service Accounts#Hash Exploitation

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice