GPEN Advanced Password Attacks Practice Question
A penetration tester is conducting a password attack against a Windows Active Directory environment. The tester has obtained a list of usernames and wants to perform a password spraying attack to avoid account lockouts. Which two considerations are most important when executing this attack? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse password spraying with brute-force, leading to selection of using large unique password lists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a small number of common passwords across many accounts.
Password spraying aims to avoid lockouts by trying a few common passwords across many accounts. The two most important considerations are using a small number of common passwords and ensuring the lockout threshold is not exceeded for any account. These directly address the goal of avoiding lockouts while maximizing coverage. The other options either describe brute-force tactics or focus on evasion rather than the fundamental spraying methodology.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform the attack during non-business hours to avoid detection.
Why it's wrong here
Performing attacks during non-business hours might reduce detection by administrators, but it is not a primary consideration for avoiding account lockouts. The key to password spraying is managing the number of attempts per account regardless of time. Additionally, off-hours attacks can still be detected by automated monitoring. This option is more about evasion than the core mechanics of spraying, making it less critical than the correct choices.
- ✗
Target only privileged accounts to maximize impact.
Why it's wrong here
While targeting privileged accounts can be valuable, focusing solely on them may miss weak passwords on regular user accounts that could provide initial access. Moreover, privileged accounts often have stricter lockout policies and monitoring. Password spraying typically targets a broad set of users to find any weak password, then escalates privileges. Limiting to privileged accounts is not a best practice for spraying and can increase detection risk.
- ✗
Use a large list of unique passwords for each account.
Why it's wrong here
Using a large list of unique passwords for each account is characteristic of a brute-force attack, not password spraying. This approach would quickly exceed lockout thresholds and is likely to lock out accounts. Password spraying specifically avoids this by using a small set of passwords across many accounts. Therefore, this option contradicts the goal of avoiding lockouts and is incorrect.
- ✓
Use a small number of common passwords across many accounts.
Why this is correct
Password spraying involves trying a few common passwords against many accounts to avoid lockout thresholds. Using a small set of passwords reduces the risk of triggering lockouts because each account is only tried a few times. This approach increases the chance of finding weak passwords without alerting security controls. It is a fundamental principle of password spraying attacks in Active Directory environments.
- ✓
Ensure the lockout threshold is not exceeded for any account.
Why this is correct
Account lockout policies are a primary defense against brute-force attacks. To avoid locking out accounts, the tester must know the lockout threshold and ensure that the number of failed attempts per account stays below it. This often means limiting attempts to one or two per account per cycle. Failing to do so can result in widespread lockouts, disrupting the environment and alerting administrators.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.