PEN-200 Password Attacks Practice Question
You have compromised a Linux system and extracted the /etc/shadow file. The root account's hash is prefixed with $6$. Which of the following statements is true regarding cracking this hash?
⚠ Common exam trap
The trap here is misinterpreting the $6$ prefix as encryption or as a different hashing algorithm, leading to incorrect cracking strategies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The hash is a SHA-512 crypt hash and can be cracked with tools like John the Ripper or Hashcat.
The $6$ prefix in /etc/shadow indicates SHA-512 crypt, a secure password hashing algorithm. It is not encryption, so it cannot be decrypted; it must be cracked. John the Ripper and Hashcat both support SHA-512 crypt and are commonly used for this purpose. The other options misidentify the algorithm or misunderstand the nature of password hashing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The hash is a SHA-512 crypt hash and can be cracked with tools like John the Ripper or Hashcat.
Why this is correct
The $6$ prefix denotes SHA-512 crypt, a key derivation function used in Linux shadow files. It is designed to be slow to resist brute-force attacks. Tools like John the Ripper and Hashcat support this format and can perform dictionary or brute-force attacks to recover the plaintext password.
- ✗
The hash is a bcrypt hash and requires the Blowfish algorithm to crack.
Why it's wrong here
Bcrypt hashes are prefixed with $2a$, $2b$, or $2y$, not $6$. The $6$ prefix specifically indicates SHA-512 crypt. Confusing the two would lead to using the wrong cracking mode, wasting time and failing to recover the password.
- ✗
The hash is a DES hash and can be cracked quickly due to its short key length.
Why it's wrong here
DES crypt hashes have no prefix or use a 13-character format. The $6$ prefix is not DES. DES is outdated and weak, but this hash is SHA-512 crypt, which is much stronger. Misidentifying it as DES would result in incorrect cracking approaches.
- ✗
The hash is encrypted with AES-256 and requires a key to decrypt.
Why it's wrong here
The $6$ prefix indicates SHA-512 crypt, not AES-256. AES is a symmetric encryption algorithm, while password hashes are one-way functions. You cannot decrypt a hash; you must crack it by trying candidate passwords. This option misidentifies the algorithm and the nature of password hashing.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.