PT0-002 Attacks and Exploits Practice Question
A tester is performing a Kerberoasting attack. After requesting TGS tickets, which hashcat mode should be used to crack them?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-m 13100
Kerberoast tickets are TGS-REP hashes, mode 13100.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
-m 1000
Why it's wrong here
Hashcat mode 1000 targets NTLM hashes (MD4 of the UTF-16LE password), which appear as 32-character hex values. A Kerberoasting capture is a TGS-REP ticket blob, not an NTLM hash, and mode 1000 cannot parse it; the wrong mode fails immediately or cracks nothing.
- ✓
-m 13100
Why this is correct
Hashcat mode 13100 is specifically designed for Kerberos 5 TGS-REP hashes in $krb5tgs$ format, typically extracted from memory (e.g., Impacket, Rubeus) or saved as .kirbi and converted. This is the correct mode because Kerberoasting yields a service ticket whose encrypted portion is encrypted with RC4-HMAC (etype 23) using the service account's NT hash.
- ✗
-m 18200
Why it's wrong here
Hashcat mode 18200 is for AS-REP hashes obtained via AS-REP roasting, which exploits accounts with preauthentication disabled. Kerberoasting uses an AS-REP to obtain TGS-REP, but the targeted hash is the TGS-REP encrypted with the service account key, not the AS-REP preauth ciphertext; mode 18200 expects a different hash layout and won't recognize a TGS-REP.
- ✗
-m 5500
Why it's wrong here
Hashcat mode 5500 is for NetNTLMv1 challenge-response hashes, which relate to NTLM authentication over the network and are captured via tools like Responder. NetNTLMv1 has a completely different format than a Kerberos TGS-REP, and mode 5500 is for NTLMv1, not for cracking a service ticket encrypted with RC4-HMAC; thus it can't be used for Kerberoasting.
Go deeper
Related to this question
Learn chapter
Debriefing the Client After a PenTest
Key term
Kerberoasting
Kerberoasting is an attack where a hacker steals service account password hashes from Active Directory to crack them offline and gain unauthorized access.
Key term
Hashcat
Hashcat is a powerful password recovery tool that uses various attack methods to crack password hashes, widely used by security professionals and penetration testers.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.