Courseiva
Password Attacks →hardMultiple Choice

PEN-200 Password Attacks Practice Question

You have compromised a Linux system and extracted the /etc/shadow file. The root account's hash is prefixed with $6$. Which of the following statements is true regarding cracking this hash?

⚠ Common exam trap

The trap here is misinterpreting the $6$ prefix as encryption or as a different hashing algorithm, leading to incorrect cracking strategies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The hash is a SHA-512 crypt hash and can be cracked with tools like John the Ripper or Hashcat.

The $6$ prefix in /etc/shadow indicates SHA-512 crypt, a secure password hashing algorithm. It is not encryption, so it cannot be decrypted; it must be cracked. John the Ripper and Hashcat both support SHA-512 crypt and are commonly used for this purpose. The other options misidentify the algorithm or misunderstand the nature of password hashing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The hash is a SHA-512 crypt hash and can be cracked with tools like John the Ripper or Hashcat.

    Why this is correct

    The $6$ prefix denotes SHA-512 crypt, a key derivation function used in Linux shadow files. It is designed to be slow to resist brute-force attacks. Tools like John the Ripper and Hashcat support this format and can perform dictionary or brute-force attacks to recover the plaintext password.

  • ✗

    The hash is a bcrypt hash and requires the Blowfish algorithm to crack.

    Why it's wrong here

    Bcrypt hashes are prefixed with $2a$, $2b$, or $2y$, not $6$. The $6$ prefix specifically indicates SHA-512 crypt. Confusing the two would lead to using the wrong cracking mode, wasting time and failing to recover the password.

  • ✗

    The hash is a DES hash and can be cracked quickly due to its short key length.

    Why it's wrong here

    DES crypt hashes have no prefix or use a 13-character format. The $6$ prefix is not DES. DES is outdated and weak, but this hash is SHA-512 crypt, which is much stronger. Misidentifying it as DES would result in incorrect cracking approaches.

  • ✗

    The hash is encrypted with AES-256 and requires a key to decrypt.

    Why it's wrong here

    The $6$ prefix indicates SHA-512 crypt, not AES-256. AES is a symmetric encryption algorithm, while password hashes are one-way functions. You cannot decrypt a hash; you must crack it by trying candidate passwords. This option misidentifies the algorithm and the nature of password hashing.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.