PEN-200 Password Attacks Practice Question
You are performing a penetration test against a Linux server and have obtained a copy of the /etc/shadow file. The file contains a hash for user 'admin' that starts with '$6$'. You want to crack this hash offline. Which hashcat mode should you use?
⚠ Common exam trap
Many candidates confuse the various '$id$' prefixes in crypt(3) hashes, leading to selection of the wrong hashcat mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mode 1800 (sha512crypt)
The '$6$' prefix in /etc/shadow denotes SHA-512 crypt, which is handled by hashcat mode 1800 (sha512crypt). The other modes correspond to different algorithms: mode 500 for md5crypt ('$1$'), mode 3200 for bcrypt ('$2a$'), and mode 7400 for sha256crypt ('$5$'). Using the correct mode is essential for successful cracking. Therefore, mode 1800 is the right choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mode 7400 (sha256crypt)
Why it's wrong here
Mode 7400 is for sha256crypt, which uses the '$5$' prefix. The hash in question starts with '$6$', indicating sha512crypt. While both are SHA-2 based, they are distinct algorithms with different modes in hashcat. Using mode 7400 would result in an error or failure to crack. This option is a near miss due to similar naming.
- ✓
Mode 1800 (sha512crypt)
Why this is correct
Mode 1800 in hashcat is specifically for sha512crypt, which corresponds to the '$6$' prefix in /etc/shadow. This is the correct mode to crack the hash. It supports the SHA-512 based crypt(3) algorithm used by most modern Linux systems. Using this mode ensures the hash is processed correctly and efficiently.
- ✗
Mode 3200 (bcrypt)
Why it's wrong here
Mode 3200 is for bcrypt hashes, which typically start with '$2a$', '$2b$', or '$2y$'. The '$6$' prefix is not bcrypt. Bcrypt is a different algorithm with a different structure. Using mode 3200 would not work for a SHA-512 crypt hash. This option confuses the hash prefix with bcrypt's format.
- ✗
Mode 500 (md5crypt)
Why it's wrong here
Mode 500 is for md5crypt hashes, which start with '$1$'. The '$6$' prefix indicates SHA-512 crypt, not MD5. Using mode 500 would fail to crack the hash. This option is a common mistake due to confusion between different crypt formats. It does not match the hash type in the scenario.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.