GCIH Understanding Passwords Practice Question
A security analyst is examining a Linux system that uses shadow password files. The analyst notices that the password hashes are stored in /etc/shadow and are prefixed with $6$. Which of the following best describes the hashing algorithm used for these passwords?
⚠ Common exam trap
Candidates often confuse the prefix for SHA-256 ($5$) with that for SHA-512 ($6$), or assuming that a high number means a more secure algorithm like bcrypt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SHA-512
The $6$ prefix in /etc/shadow explicitly indicates the use of SHA-512 for password hashing. This is part of the crypt(3) library format. While SHA-512 is a cryptographic hash function, it is not inherently slow, so it is often used with a salt to prevent rainbow table attacks. Understanding these prefixes helps incident handlers quickly identify the hashing algorithm in use.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MD5
Why it's wrong here
MD5 hashes in shadow files are prefixed with $1$. The $6$ prefix indicates a different algorithm. MD5 is considered weak for password storage due to its speed and vulnerability to collision attacks, and it is not used here.
- ✗
SHA-256
Why it's wrong here
SHA-256 hashes in shadow files are prefixed with $5$. The $6$ prefix corresponds to SHA-512, not SHA-256. SHA-256 is stronger than MD5 but still not as robust as SHA-512 for password hashing in terms of output length.
- ✗
bcrypt
Why it's wrong here
bcrypt hashes in shadow files are typically prefixed with $2a$, $2b$, or $2y$. The $6$ prefix is not used for bcrypt. bcrypt is a key derivation function designed to be slow, making it more resistant to brute-force attacks than SHA-512.
- ✓
SHA-512
Why this is correct
In Linux shadow files, the prefix $6$ denotes the SHA-512 hashing algorithm. This is a common default on many modern Linux distributions. SHA-512 produces a longer hash and is more resistant to brute-force attacks than MD5 or SHA-256, though it is still a fast hash and should be combined with salting and key stretching.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.