CEH Web Application and Injection Attacks Practice Question
An attacker attempts to log into a web application by trying many common passwords for a list of known usernames. Which type of authentication attack is this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password spraying
Password spraying involves using a few common passwords against many usernames to avoid account lockouts, as opposed to brute force (many passwords on one account) or credential stuffing (using known username/password pairs).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dictionary attack
Why it's wrong here
Dictionary attack tries many passwords from a list on a single account.
- ✗
Credential stuffing
Why it's wrong here
Credential stuffing uses known username/password pairs from breaches.
- ✓
Password spraying
Why this is correct
Password spraying uses a few common passwords across many accounts.
- ✗
Brute force attack
Why it's wrong here
Brute force would try many passwords on a single account.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.