When performing a password spraying attack, why is it considered best practice to use a single common password against many accounts rather than many passwords against one account?
Spraying a single common password across many accounts increases the statistical likelihood of hitting at least one user who utilizes that password. This method is specifically designed to maximize credential acquisition while staying beneath the radar of lockout policies that are configured to monitor individual account failures.
Why this answer
Password spraying leverages the low frequency of attempts per account to evade account lockout thresholds while maximizing the probability of finding at least one compromised credential. This approach is highly effective in enterprise environments where account policies restrict the number of failed login attempts per user. By spreading attempts, an attacker bypasses these security controls, whereas targeted brute-forcing of a single user would quickly trigger a lockout and alert security teams.
Exam trap
Test-takers frequently confuse password spraying with brute-forcing, incorrectly assuming the goal is to guess one user's password through massive volume.