PEN-200 Password Attacks Practice Question
When performing a password spraying attack, why is it considered best practice to use a single common password against many accounts rather than many passwords against one account?
⚠ Common exam trap
Test-takers frequently confuse password spraying with brute-forcing, incorrectly assuming the goal is to guess one user's password through massive volume.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It increases the number of accounts that can be compromised simultaneously.
Password spraying leverages the low frequency of attempts per account to evade account lockout thresholds while maximizing the probability of finding at least one compromised credential. This approach is highly effective in enterprise environments where account policies restrict the number of failed login attempts per user. By spreading attempts, an attacker bypasses these security controls, whereas targeted brute-forcing of a single user would quickly trigger a lockout and alert security teams.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It increases the number of accounts that can be compromised simultaneously.
Why this is correct
Spraying a single common password across many accounts increases the statistical likelihood of hitting at least one user who utilizes that password. This method is specifically designed to maximize credential acquisition while staying beneath the radar of lockout policies that are configured to monitor individual account failures.
- ✗
It is faster for the tool to process a single password.
Why it's wrong here
While it might be marginally faster to use one password, speed is not the reason for the technique. The primary driver is evading account lockout mechanisms. If an attacker only cared about speed, they would use multi-threaded brute-forcing, which is much more likely to trigger defensive alerts.
- ✗
It prevents the detection of the attack by network firewalls.
Why it's wrong here
Network firewalls typically monitor traffic patterns, not account lockout status. Spraying might be less noisy for EDR or identity monitoring, but it does not inherently evade network-level firewalls. The strategy is purely about circumventing application or domain controller lockout thresholds, not network-level detection of traffic volume.
- ✗
It guarantees that the password will be found for every user.
Why it's wrong here
Password spraying does not guarantee success for every user; it is a probability-based technique. Users with strong or unique passwords will not be compromised. The benefit is solely in the efficiency and stealth of gaining access to a subset of accounts without triggering security automated responses.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.