GPEN Password Attacks and Formats Practice Question
A penetration tester obtains a password hash from a Linux system's /etc/shadow file that begins with $6$. Which statement correctly describes this hash and its implications for cracking?
⚠ Common exam trap
Candidates often confuse the $6$ prefix with other common hash identifiers like $5$ for SHA-256 or $2a$ for bcrypt, leading to selection of an incompatible Hashcat mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is a SHA-512 crypt hash and can be cracked using Hashcat mode 1800.
The $6$ prefix in /etc/shadow indicates SHA-512 crypt. Hashcat mode 1800 is the correct mode for cracking sha512crypt hashes. Other modes correspond to different algorithms: mode 500 for md5crypt, mode 3200 for bcrypt, and mode 7400 for sha256crypt. Identifying the prefix correctly is essential to select the right cracking mode and avoid wasted effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is a bcrypt hash and can be cracked using Hashcat mode 3200.
Why it's wrong here
Bcrypt hashes start with $2a$, $2b$, or $2y$, not $6$. Hashcat mode 3200 is for bcrypt. While bcrypt is also a strong password hashing algorithm, the prefix $6$ unambiguously indicates SHA-512 crypt. Mistaking it for bcrypt would lead to using an incorrect mode and wasting cracking effort, as the hash formats are incompatible.
- ✓
It is a SHA-512 crypt hash and can be cracked using Hashcat mode 1800.
Why this is correct
The $6$ prefix is the standard identifier for SHA-512 crypt in Linux shadow files. Hashcat mode 1800 is specifically designed for sha512crypt, which includes the salt and iteration count. This mode handles the variable rounds and salt, making it the correct choice for cracking this hash. Using the wrong mode would result in failure to recognize the hash format.
- ✗
It is a SHA-256 crypt hash and can be cracked using Hashcat mode 7400.
Why it's wrong here
SHA-256 crypt uses the prefix $5$, not $6$. Hashcat mode 7400 is for sha256crypt. The $6$ prefix specifically denotes SHA-512 crypt, which is a different algorithm with a different mode. Using mode 7400 would not correctly parse the hash, resulting in errors. It is crucial to match the prefix to the correct Hashcat mode for successful cracking.
- ✗
It is an MD5-based hash and can be cracked using Hashcat mode 500.
Why it's wrong here
The $6$ prefix indicates SHA-512 crypt, not MD5. MD5 crypt is denoted by $1$, and Hashcat mode 500 is for md5crypt. Using mode 500 would fail to parse the hash correctly, leading to errors or no cracks. The scenario requires recognizing the prefix and selecting the appropriate mode, such as 1800 for sha512crypt.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.