Courseiva
Password Attacks →easyMultiple Choice

PEN-200 Password Attacks Practice Question

You are performing a penetration test against a Linux server and have obtained a copy of the /etc/shadow file. The file contains a hash for user 'admin' that starts with '$6$'. You want to crack this hash offline. Which hashcat mode should you use?

⚠ Common exam trap

Many candidates confuse the various '$id$' prefixes in crypt(3) hashes, leading to selection of the wrong hashcat mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mode 1800 (sha512crypt)

The '$6$' prefix in /etc/shadow denotes SHA-512 crypt, which is handled by hashcat mode 1800 (sha512crypt). The other modes correspond to different algorithms: mode 500 for md5crypt ('$1$'), mode 3200 for bcrypt ('$2a$'), and mode 7400 for sha256crypt ('$5$'). Using the correct mode is essential for successful cracking. Therefore, mode 1800 is the right choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mode 7400 (sha256crypt)

    Why it's wrong here

    Mode 7400 is for sha256crypt, which uses the '$5$' prefix. The hash in question starts with '$6$', indicating sha512crypt. While both are SHA-2 based, they are distinct algorithms with different modes in hashcat. Using mode 7400 would result in an error or failure to crack. This option is a near miss due to similar naming.

  • ✓

    Mode 1800 (sha512crypt)

    Why this is correct

    Mode 1800 in hashcat is specifically for sha512crypt, which corresponds to the '$6$' prefix in /etc/shadow. This is the correct mode to crack the hash. It supports the SHA-512 based crypt(3) algorithm used by most modern Linux systems. Using this mode ensures the hash is processed correctly and efficiently.

  • ✗

    Mode 3200 (bcrypt)

    Why it's wrong here

    Mode 3200 is for bcrypt hashes, which typically start with '$2a$', '$2b$', or '$2y$'. The '$6$' prefix is not bcrypt. Bcrypt is a different algorithm with a different structure. Using mode 3200 would not work for a SHA-512 crypt hash. This option confuses the hash prefix with bcrypt's format.

  • ✗

    Mode 500 (md5crypt)

    Why it's wrong here

    Mode 500 is for md5crypt hashes, which start with '$1$'. The '$6$' prefix indicates SHA-512 crypt, not MD5. Using mode 500 would fail to crack the hash. This option is a common mistake due to confusion between different crypt formats. It does not match the hash type in the scenario.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.