Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A tester is performing a Kerberoasting attack. After requesting TGS tickets, which hashcat mode should be used to crack them?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

-m 13100

Kerberoast tickets are TGS-REP hashes, mode 13100.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    -m 1000

    Why it's wrong here

    Hashcat mode 1000 targets NTLM hashes (MD4 of the UTF-16LE password), which appear as 32-character hex values. A Kerberoasting capture is a TGS-REP ticket blob, not an NTLM hash, and mode 1000 cannot parse it; the wrong mode fails immediately or cracks nothing.

  • ✓

    -m 13100

    Why this is correct

    Hashcat mode 13100 is specifically designed for Kerberos 5 TGS-REP hashes in $krb5tgs$ format, typically extracted from memory (e.g., Impacket, Rubeus) or saved as .kirbi and converted. This is the correct mode because Kerberoasting yields a service ticket whose encrypted portion is encrypted with RC4-HMAC (etype 23) using the service account's NT hash.

  • ✗

    -m 18200

    Why it's wrong here

    Hashcat mode 18200 is for AS-REP hashes obtained via AS-REP roasting, which exploits accounts with preauthentication disabled. Kerberoasting uses an AS-REP to obtain TGS-REP, but the targeted hash is the TGS-REP encrypted with the service account key, not the AS-REP preauth ciphertext; mode 18200 expects a different hash layout and won't recognize a TGS-REP.

  • ✗

    -m 5500

    Why it's wrong here

    Hashcat mode 5500 is for NetNTLMv1 challenge-response hashes, which relate to NTLM authentication over the network and are captured via tools like Responder. NetNTLMv1 has a completely different format than a Kerberos TGS-REP, and mode 5500 is for NTLMv1, not for cracking a service ticket encrypted with RC4-HMAC; thus it can't be used for Kerberoasting.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.