Courseiva
Password Attacks →easyMultiple Choice

PEN-200 Password Attacks Practice Question

When performing a password spraying attack, why is it considered best practice to use a single common password against many accounts rather than many passwords against one account?

⚠ Common exam trap

Test-takers frequently confuse password spraying with brute-forcing, incorrectly assuming the goal is to guess one user's password through massive volume.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It increases the number of accounts that can be compromised simultaneously.

Password spraying leverages the low frequency of attempts per account to evade account lockout thresholds while maximizing the probability of finding at least one compromised credential. This approach is highly effective in enterprise environments where account policies restrict the number of failed login attempts per user. By spreading attempts, an attacker bypasses these security controls, whereas targeted brute-forcing of a single user would quickly trigger a lockout and alert security teams.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It increases the number of accounts that can be compromised simultaneously.

    Why this is correct

    Spraying a single common password across many accounts increases the statistical likelihood of hitting at least one user who utilizes that password. This method is specifically designed to maximize credential acquisition while staying beneath the radar of lockout policies that are configured to monitor individual account failures.

  • ✗

    It is faster for the tool to process a single password.

    Why it's wrong here

    While it might be marginally faster to use one password, speed is not the reason for the technique. The primary driver is evading account lockout mechanisms. If an attacker only cared about speed, they would use multi-threaded brute-forcing, which is much more likely to trigger defensive alerts.

  • ✗

    It prevents the detection of the attack by network firewalls.

    Why it's wrong here

    Network firewalls typically monitor traffic patterns, not account lockout status. Spraying might be less noisy for EDR or identity monitoring, but it does not inherently evade network-level firewalls. The strategy is purely about circumventing application or domain controller lockout thresholds, not network-level detection of traffic volume.

  • ✗

    It guarantees that the password will be found for every user.

    Why it's wrong here

    Password spraying does not guarantee success for every user; it is a probability-based technique. Users with strong or unique passwords will not be compromised. The benefit is solely in the efficiency and stealth of gaining access to a subset of accounts without triggering security automated responses.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.