PEN-200 Password Attacks Practice Question
You have compromised a Linux host and extracted the /etc/shadow file. The file contains a hash starting with `$6$`. Which hashing algorithm does this prefix indicate?
⚠ Common exam trap
The trap here is mixing up the numeric prefixes for different crypt algorithms, such as `$5$` for SHA-256crypt or `$1$` for MD5crypt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SHA-512crypt
In the modular crypt format, the prefix before the second `$` indicates the hashing algorithm. `$6$` is the standard identifier for SHA-512crypt, which is commonly used on modern Linux systems for storing password hashes in /etc/shadow. Recognizing this prefix allows a penetration tester to choose the correct cracking tool and mode, such as Hashcat mode 1800 or John the Ripper's sha512crypt format, to efficiently recover plaintext passwords.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MD5crypt
Why it's wrong here
MD5crypt hashes start with `$1$`. The `$6$` prefix is not associated with MD5. MD5crypt is an older algorithm and is considered weak due to MD5's vulnerabilities. While it may still be encountered on legacy systems, it is not the algorithm indicated here. Selecting this would result in using an incorrect cracking mode and failing to recover the password efficiently.
- ✓
SHA-512crypt
Why this is correct
The `$6$` prefix in /etc/shadow indicates SHA-512crypt, a widely used password hashing algorithm on Linux systems. It is based on the SHA-512 algorithm and includes a salt to protect against rainbow table attacks. Knowing the algorithm is crucial for selecting the correct cracking mode in tools like Hashcat (mode 1800) or John the Ripper (format sha512crypt). This prefix is part of the modular crypt format used by many Unix-like systems.
- ✗
SHA-256crypt
Why it's wrong here
SHA-256crypt hashes start with `$5$`, not `$6$`. The `$6$` prefix specifically denotes SHA-512crypt. Both are part of the same family but use different SHA variants. Using the wrong mode (e.g., mode 7400 for SHA-256crypt in Hashcat) would not work for a `$6$` hash. Therefore, this option is incorrect and would lead to unsuccessful cracking attempts.
- ✗
bcrypt
Why it's wrong here
bcrypt hashes typically start with `$2a$`, `$2b$`, or `$2y$`, not `$6$`. bcrypt is a key derivation function designed for password hashing and is used in some Linux distributions and web applications, but it is not indicated by the `$6$` prefix. Confusing the two could lead to using the wrong cracking mode, wasting time. Therefore, this option is incorrect for the given hash prefix.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.