20+ practice questions focused on Password Attacks — one of the most tested topics on the OffSec PEN-200 / OSCP Concepts exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Password Attacks PracticeWhen performing a password spraying attack against an O365 or Azure AD environment, which TWO factors are most likely to increase the risk of detection or account lockout?
Explanation: Password spraying involves testing a single password against many accounts to avoid triggering lockout thresholds. However, excessive volume and specific security controls can lead to immediate detection. Identifying these risks is crucial for an OSCP practitioner to balance the need for discovery with the requirement to remain undetected. Monitoring for anomalous login patterns or failing to account for intelligent lockout policies will often result in the engagement being compromised.
Which THREE of the following are common indicators that an organization is vulnerable to Kerberoasting?
Explanation: Kerberoasting exploits the way Windows handles service accounts by requesting service tickets for accounts with Service Principal Names (SPNs). Identifying these indicators is essential for lateral movement. A successful attack allows an attacker to crack service account passwords offline. Recognizing these signs helps in assessing the risk of privilege escalation within a Windows domain, as most environments have at least one misconfigured or over-privileged service account susceptible to this technique.
You have gained access to a Linux machine and extracted the shadow file. Which THREE of the following are valid strategies for recovering the plaintext passwords from the hashes provided?
Explanation: Recovering passwords from the `/etc/shadow` file requires understanding the hash format and appropriate tools for the job. In a professional engagement, choosing the right strategy—whether it is automated cracking or targeted analysis—is vital. These methods represent the core techniques for offline password recovery on Linux, and mastery of them is essential for successfully transitioning from initial access to full credential compromise on target systems.
What is the primary risk of performing a password spray against an organization that has implemented a third-party Single Sign-On (SSO) solution?
Explanation: SSO solutions centralize authentication, which means a single point of failure can lead to widespread compromise. However, from an attacker's perspective, spraying an SSO provider often triggers centralized logging and protection mechanisms that are much more robust than those on individual applications. This makes detection significantly more likely. Understanding the architecture of SSO is important for assessing the risk of account lockout and account compromise.
Which TWO actions are considered best practices for securing service accounts against password-based attacks?
Explanation: Securing service accounts is a fundamental component of defending an AD environment. These accounts are often over-privileged and rarely monitored, making them high-value targets. By following these best practices, an organization can significantly reduce the risk of an attacker gaining a foothold via a service account. Recognizing these defenses is important for an OSCP practitioner to provide actionable recommendations after identifying potential vulnerabilities during an assessment.
+15 more Password Attacks questions available
Practice all Password Attacks questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Password Attacks. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Password Attacks questions on the PEN-200 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Password Attacks is tested as part of the OffSec PEN-200 / OSCP Concepts blueprint. Practicing with targeted Password Attacks questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free PEN-200 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Password Attacks is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Password Attacks practice session with instant scoring and detailed explanations.
Start Password Attacks Practice →