In the /etc/shadow file, a user's password hash begins with '$6$'. What hash algorithm does this prefix indicate?
The `$6$` prefix in `/etc/shadow` specifies SHA-512, as defined by the crypt(3) scheme identifiers. This satisfies the stem's requirement to identify the algorithm from the hash prefix, distinguishing it from `$1$` (MD5), `$5$` (SHA-256) and `$2$` (bcrypt).
Why this answer
The prefix '$6$' in the /etc/shadow file indicates that the password hash was generated using the SHA-512 (Secure Hash Algorithm 512-bit) algorithm. This is defined in the crypt(3) function's modular crypt format, where $1$ is MD5, $5$ is SHA-256, and $6$ is SHA-512. SHA-512 is the strongest of the commonly used hash algorithms in Linux password hashing, providing a 512-bit digest.
Exam trap
The trap here is that candidates often confuse the prefix '$6$' with SHA-256 (which uses '$5$') or mistakenly associate '$6$' with Blowfish due to similar numbering, but the correct mapping is $1$=MD5, $5$=SHA-256, $6$=SHA-512.
How to eliminate wrong answers
Option B (SHA-256) is wrong because SHA-256 uses the prefix '$5$', not '$6$'. Option C (MD5) is wrong because MD5 uses the prefix '$1$', and it is considered cryptographically broken for password storage. Option D (Blowfish) is wrong because Blowfish-based bcrypt uses the prefix '$2a$', '$2b$', or '$2y$', not '$6$'.