CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

A penetration tester compromises a low-privilege domain account and then requests service tickets for several service principal names (SPNs) from the domain controller. The tester extracts the encrypted portions of these tickets and attempts to crack them offline to recover service account passwords. Which attack technique is being performed?

  1. ALDAP injection
  2. BPass-the-ticket attack
  3. CKerberoasting
  4. DGolden ticket attack
Show answer & explanation

Correct answer: C. Kerberoasting

Kerberoasting involves requesting service tickets (TGS) for accounts with SPNs and then cracking the encrypted ticket offline to recover the service account's plaintext password, since these tickets are encrypted with the service account's password hash.

Why the other options are wrong

  • A. LDAP injection manipulates directory queries, unrelated to Kerberos ticket cracking.
  • B. Pass-the-ticket reuses a stolen valid ticket rather than cracking it offline.
  • D. A golden ticket attack forges a Kerberos TGT using the compromised krbtgt account hash, not cracking service tickets.

Kerberoasting

An attack where a low-privilege user requests Kerberos service tickets for SPNs and cracks them offline to recover service account passwords.

  • Targets service accounts with weak passwords
  • Ticket is encrypted with the service account's NTLM hash
  • Mitigated by strong/long service account passwords and managed service accounts

Memory trick: Kerberoasting roasts service tickets over an offline cracking fire.

More Threats, Vulnerabilities, and Mitigations questions