GPEN Password Attacks and Formats Practice Question
During an engagement, a penetration tester obtains a password hash that starts with `$2y$10$`. The client's security policy requires passwords to be at least 12 characters and include complexity. The tester wants to crack the hash using a rule-based attack. Which Hashcat mode should be used, and what is the primary advantage of this hash format?
⚠ Common exam trap
It's easy for candidates to confuse bcrypt's cost factor with a simple iteration count, leading to underestimating the time required for cracking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mode 3200 (bcrypt), and the advantage is that the cost factor makes brute-force attacks significantly slower.
The hash prefix `$2y$10$` is characteristic of bcrypt, with the cost factor 10. Hashcat mode 3200 is designed for bcrypt. The cost factor exponentially increases the number of iterations, making each guess computationally expensive. This slows down brute-force and rule-based attacks, which is the main security benefit. A penetration tester must recognize this and adjust expectations for cracking speed and time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mode 1000 (NTLM), and the advantage is that it is the default Windows hash format, making it widely applicable.
Why it's wrong here
Mode 1000 is for NTLM hashes, which are used in Windows environments and have no prefix like `$2y$`. NTLM hashes are unsalted and fast to crack, which is a vulnerability, not an advantage. This option misidentifies the hash and the platform. Using mode 1000 would fail to crack the bcrypt hash and demonstrate a lack of understanding of hash formats.
- ✓
Mode 3200 (bcrypt), and the advantage is that the cost factor makes brute-force attacks significantly slower.
Why this is correct
The `$2y$` prefix indicates bcrypt, and the `10` is the cost factor (2^10 iterations). Hashcat mode 3200 is correct for bcrypt. The cost factor increases the computational effort per guess, making brute-force and rule-based attacks much slower. This is the primary defensive advantage of bcrypt, and the tester must account for it when planning the attack.
- ✗
Mode 500 (md5crypt), and the advantage is that it is fast to compute, allowing more guesses per second.
Why it's wrong here
Mode 500 is for MD5 crypt, indicated by `$1$`. The hash prefix `$2y$` is bcrypt, not MD5. MD5 crypt is indeed fast, but that is a disadvantage for password storage, not an advantage. Choosing this mode would be incorrect and ineffective for cracking the given hash. The speed would not help because the hash format does not match.
- ✗
Mode 1800 (sha512crypt), and the advantage is that the salt prevents rainbow table attacks.
Why it's wrong here
Mode 1800 is for SHA-512 crypt, which uses the `$6$` prefix, not `$2y$`. The salt in SHA-512 crypt does prevent rainbow tables, but that is not the format here. Using the wrong mode would result in no hashes being cracked, wasting time and resources. The tester must correctly identify bcrypt to select the appropriate mode.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.