Courseiva
Attacking Passwords →mediumMultiple Select

GCIH Attacking Passwords Practice Question

A penetration tester is performing a password attack against an Active Directory environment. The tester has obtained a list of valid domain usernames and wants to identify accounts with weak passwords without locking out accounts. The domain account lockout policy is set to lock accounts after five failed attempts within 30 minutes. Which two of the following techniques would allow the tester to test passwords while minimizing the risk of account lockout? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any password attack can be made lockout-safe with delays, when in fact only techniques that limit attempts per account per lockout window truly avoid lockouts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a tool that performs a single authentication attempt per account per lockout window

Password spraying and single-attempt-per-window techniques are both designed to test passwords while staying under lockout thresholds. Spraying uses one password across many accounts, and single-attempt-per-window limits each account to one guess per lockout period. Both avoid triggering the five-failure lockout, unlike brute-forcing or credential stuffing, which can rapidly exceed the threshold.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using a pass-the-hash attack with captured NTLM hashes

    Why it's wrong here

    Pass-the-hash uses captured NTLM hashes to authenticate without knowing the plaintext password, bypassing the need to guess passwords. However, it requires prior compromise to obtain hashes and does not help in testing password strength from a list of usernames. It is not a password-guessing technique and does not address the lockout concern in this scenario.

  • ✓

    Using a tool that performs a single authentication attempt per account per lockout window

    Why this is correct

    Limiting each account to one failed attempt per lockout window ensures the account never reaches the lockout threshold. Tools like Spray or custom scripts can enforce this by tracking attempts and waiting the requisite time. This approach allows the tester to test one password per account per window, gradually building a list of valid credentials without locking accounts.

  • ✗

    Brute-forcing each account with a large dictionary until a valid password is found

    Why it's wrong here

    Brute-forcing a single account with many password guesses will quickly exceed the five-failure lockout threshold, locking the account. This not only alerts defenders but also prevents further testing against that account until the lockout duration expires. It is the opposite of a lockout-aware strategy and is not appropriate when lockout policies are enforced.

  • ✓

    Password spraying with a single common password against all accounts, waiting between attempts

    Why this is correct

    Password spraying tries one password against many accounts, spacing attempts to stay below the lockout threshold per account. By using a single password and waiting between rounds, the tester avoids triggering the five-failure lockout for any individual account. This technique is effective for finding accounts with common weak passwords like 'Password123' without causing widespread lockouts.

  • ✗

    Performing a credential stuffing attack using passwords from previous breaches

    Why it's wrong here

    Credential stuffing uses known username/password pairs from other breaches, but it still involves multiple authentication attempts per account if the first guess fails. If the tester tries several breached passwords for a single account, the lockout threshold can be reached. Without careful rate limiting, credential stuffing can cause lockouts and is not inherently lockout-safe.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.