You are conducting a penetration test against an organizatio - CompTIA Pentest+ PT0-003

Question

You are conducting a penetration test against an organization's Windows network. You have dumped the hash of their krbtgt account from the server's memory and used it to create golden tickets. Which of the following types of privilege escalation have you performed?

Answers
  1. correct
Explanation

The correct answer is B) Kerberoasting.

Kerberoasting: In a Windows network, the krbtgt account is a key component of the Kerberos authentication process. By dumping the hash of the krbtgt account from the server's memory and creating golden tickets, you are essentially exploiting the Kerberos authentication protocol. Kerberoasting is the process of extracting service account ticket hashes from the Ticket Granting Service (TGS), and in this case, you're using the krbtgt account hash to create a golden ticket, which allows you to impersonate any user, including privileged accounts. This is a method of privilege escalation because it grants the attacker unrestricted access to the network resources, bypassing normal authentication.

Why the others are incorrect:

  • DLL hijacking: DLL hijacking is a method where an attacker places a malicious DLL file in a location where a legitimate process will load it. This is typically used to escalate privileges in a local environment, but it is not related to the creation of golden tickets or Kerberos attacks.

  • Insecure sudo: Insecure sudo refers to a situation in Unix/Linux environments where an unprivileged user has the ability to run certain commands with elevated privileges via the sudo command. This is not related to Windows or Kerberos and does not apply to the creation of golden tickets.

  • cPassword extraction: cPassword is a registry key used in older versions of Windows (prior to Windows 10) to store credentials for encrypted services. Extracting cPassword would be a method of credential extraction, but it does not involve creating golden tickets or exploiting the Kerberos protocol.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered