Courseiva
Attacking Passwords →easyMultiple Choice

GCIH Attacking Passwords Practice Question

Which of the following describes a 'Password Spraying' attack, and why is it preferred by attackers over traditional brute-force methods against a target domain?

⚠ Common exam trap

Candidates frequently confuse password spraying with credential stuffing. They fail to realize that spraying uses one password against many accounts, whereas stuffing uses many credentials against one or more targets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using one common password against many different accounts

Password spraying involves testing a single, common password against a large list of accounts rather than testing many passwords against one account. It is preferred because it avoids triggering account lockout thresholds, which are designed to detect traditional brute-force attacks. By keeping the authentication frequency low per account, attackers can stay under the radar of automated security monitoring systems while significantly increasing the likelihood of compromising at least one account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Testing thousands of passwords against a single high-privileged account

    Why it's wrong here

    Testing many passwords against a single account is defined as a traditional brute-force attack. This method is easily detected by account lockout policies, which lock the account after a small number of failed attempts, making it ineffective for modern secure environments.

  • ✓

    Using one common password against many different accounts

    Why this is correct

    Password spraying is characterized by the 'low and slow' approach of testing a single password against many accounts. This minimizes failed attempts per account, ensuring that individual user accounts remain active and that the attacker does not trigger account lockout mechanisms during the process.

  • ✗

    Capturing hashes via packet sniffing and offline cracking

    Why it's wrong here

    Capturing hashes is a passive reconnaissance or intercept technique. Password spraying is an active authentication attempt against a target service, not an offline process. The two techniques are distinct in their methodology and their interaction with the target's authentication infrastructure.

  • ✗

    Injecting malicious code into the authentication form

    Why it's wrong here

    Injecting code into an authentication form is a form of Cross-Site Scripting (XSS) or SQL injection. Password spraying is a legitimate, albeit malicious, use of the authentication protocol where the attacker provides credentials they expect the server to evaluate.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.