Courseiva
Attacking Passwords →hardMultiple Choice

GCIH Attacking Passwords Practice Question

An incident responder is investigating a compromised Linux server and finds that an attacker added a new user account with a password hash in /etc/shadow. The hash begins with $6$ and includes a salt. The attacker later cracked this hash offline. Which property of the hash allowed the attacker to crack it despite the salt?

⚠ Common exam trap

The trap here is believing that a salted hash cannot be cracked offline, when in reality the salt is stored with the hash and only prevents precomputation, not targeted guessing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The salt is stored alongside the hash and is not secret, so the attacker could use it to compute candidate hashes for each password guess.

Salts are stored with the hash and are not secret, so they do not prevent offline dictionary or brute-force attacks. They only defeat precomputed rainbow tables and ensure unique hashes for identical passwords. An attacker who obtains the shadow file can read the salt and compute candidate hashes for each guess, eventually recovering weak passwords. Strong, unique passwords and slow hashing algorithms are the real defenses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The $6$ prefix indicates a weak algorithm that can be reversed mathematically to recover the password.

    Why it's wrong here

    The $6$ prefix indicates SHA-512 crypt, which is a strong one-way hashing scheme, not reversible. Cryptographic hash functions are designed to be one-way, so the password cannot be mathematically reversed. The attacker cracked it through guessing and comparison, not by reversing the algorithm, and mischaracterizing SHA-512 crypt as weak is incorrect.

  • ✓

    The salt is stored alongside the hash and is not secret, so the attacker could use it to compute candidate hashes for each password guess.

    Why this is correct

    Salts are stored in the shadow file in plaintext alongside the hash. Their purpose is to prevent precomputed rainbow tables and to ensure identical passwords produce different hashes, but they do not slow down a targeted dictionary attack. An attacker who knows the salt can compute the hash for each candidate password and compare, so salting alone does not prevent offline cracking.

  • ✗

    The salt was generated using a predictable pattern, allowing the attacker to precompute a rainbow table for that specific salt.

    Why it's wrong here

    Even if the salt were predictable, building a rainbow table for a single salt offers no advantage over a direct dictionary attack with that salt. Salts are typically random, but the real reason cracking succeeded is that the attacker could compute hashes for guesses using the known salt. Predictability of the salt is not the core issue here.

  • ✗

    The hash was generated with a low iteration count, making it trivial to compute but not explaining how the salt was bypassed.

    Why it's wrong here

    Iteration count affects the cost per guess, but the scenario states the hash was cracked offline, and the question asks which property allowed cracking despite the salt. Iteration count does not bypass the salt; the attacker still uses the salt. While a low iteration count would make cracking faster, it is not the property that explains why the salt did not prevent the attack.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.