GPEN Password Attacks and Formats Practice Question
A penetration tester extracts a password hash from a compromised Linux system. The hash format is `$6$rounds=5000$abcdefgh$...`. Which hashing algorithm and configuration does this represent?
⚠ Common exam trap
The trap here is assuming that a numeric parameter like 5000 always refers to a cost factor rather than an iteration count, which can lead to using the wrong cracking tool settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SHA-512 crypt with 5000 rounds and salt 'abcdefgh'
The hash begins with `$6$`, which is the standard identifier for SHA-512 crypt. The `rounds=5000` indicates the iteration count, and the following string is the salt. This format is widely used on Linux systems for password storage. A penetration tester must recognize the prefix to select the correct cracking mode, such as Hashcat mode 1800, and configure the tool accordingly to attempt recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SHA-256 crypt with 5000 rounds and salt 'abcdefgh'
Why it's wrong here
SHA-256 crypt uses the prefix `$5$`, while SHA-512 crypt uses `$6$`. The two are similar in design but produce different hash lengths and use different underlying algorithms. Mistaking `$6$` for SHA-256 would result in an incorrect cracking configuration and failure to recover the password.
- ✗
MD5 crypt with 5000 rounds and salt 'abcdefgh'
Why it's wrong here
MD5 crypt is indicated by the prefix `$1$`. The hash shown uses `$6$`, which is SHA-512 crypt. MD5 crypt does not support a rounds parameter in the same way; it uses a fixed number of iterations. Confusing the two would lead the tester to use the wrong cracking mode and waste time.
- ✗
bcrypt with cost factor 5000 and salt 'abcdefgh'
Why it's wrong here
bcrypt hashes start with `$2a$`, `$2b$`, or `$2y$`, not `$6$`. The cost factor in bcrypt is logarithmic and typically between 4 and 31, not 5000. This option misidentifies the algorithm and the meaning of the numeric parameter, which here indicates iteration count rather than cost.
- ✓
SHA-512 crypt with 5000 rounds and salt 'abcdefgh'
Why this is correct
The prefix `$6$` denotes SHA-512 crypt, the `rounds=5000` parameter specifies the number of iterations, and `abcdefgh` is the salt. This is a common format in /etc/shadow on modern Linux systems. The tester must use a tool that supports SHA-512 crypt, such as Hashcat mode 1800 or John the Ripper with the crypt format.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.