Courseiva

GPEN Advanced Password Attacks Practice Question

A penetration tester has captured a password hash from a Linux system and identifies it as a SHA-512 crypt hash. Which Hashcat mode should be used to crack this hash?

⚠ Common exam trap

Many exam-takers confuse SHA-512 crypt with other Unix crypt variants like MD5, bcrypt, or SHA-256 crypt, which have different prefixes and require different Hashcat modes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mode 1800 (sha512crypt, SHA512(Unix))

Linux systems often store password hashes in /etc/shadow using SHA-512 crypt, identified by the $6$ prefix. Hashcat mode 1800 is the correct mode to crack these hashes. Other modes like 500, 3200, or 7400 target different algorithms and would not successfully crack the SHA-512 crypt hash, leading to wasted effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mode 500 (md5crypt, MD5(Unix))

    Why it's wrong here

    Mode 500 is used for MD5-based Unix crypt hashes, which start with $1$. SHA-512 crypt hashes start with $6$ and use a different algorithm. Using mode 500 would not correctly parse or crack a SHA-512 hash, resulting in failure. Therefore, it is not the appropriate mode for the given hash.

  • ✓

    Mode 1800 (sha512crypt, SHA512(Unix))

    Why this is correct

    SHA-512 crypt hashes are commonly found in /etc/shadow on Linux systems and are identified by the $6$ prefix. Hashcat mode 1800 is specifically designed to crack these hashes. Since the scenario involves a SHA-512 crypt hash, mode 1800 is the correct choice for an efficient and successful cracking attempt.

  • ✗

    Mode 7400 (sha256crypt, SHA256(Unix))

    Why it's wrong here

    Mode 7400 targets SHA-256 crypt hashes, which start with $5$. While similar to SHA-512 crypt, they are different algorithms. The scenario specifies a SHA-512 crypt hash, so mode 7400 would not work. It is a plausible distractor because both are Unix crypt variants, but the hash prefix and algorithm differ.

  • ✗

    Mode 3200 (bcrypt)

    Why it's wrong here

    Bcrypt hashes start with $2a$, $2b$, or $2y$ and are used by some applications, not typically for Linux shadow files. SHA-512 crypt is distinct from bcrypt. Using mode 3200 would not match the hash format and would fail to crack the SHA-512 hash. Thus, it is incorrect for this scenario.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.