Courseiva
Password Attacks →mediumMultiple Choice

PEN-200 Password Attacks Practice Question

You are conducting a password spraying attack against an Active Directory environment. You have a list of common passwords and a list of usernames. To avoid locking out accounts, which approach should you take?

⚠ Common exam trap

Watch out — candidates often confuse password spraying with brute-forcing, leading to techniques that concentrate attempts on few accounts and trigger lockouts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Spray one password against all usernames, then wait 30 minutes before trying the next password.

Password spraying avoids lockouts by trying a single password against many accounts, then waiting before the next password. This keeps the number of failed attempts per account below the lockout threshold within the observation window. Trying all passwords against one account or using high concurrency increases lockout risk. Rotating subsets without waiting can also accumulate attempts. Thus, spraying one password at a time with a delay is the correct approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Try all passwords against one username before moving to the next username.

    Why it's wrong here

    This is a brute-force attack against a single account, which will quickly trigger account lockout if the lockout threshold is low. It does not spread attempts across accounts and is likely to lock the targeted account. This approach is inefficient and risky in a typical AD environment with lockout policies. It contradicts the goal of avoiding lockouts.

  • ✗

    Use a tool like Hydra to perform a dictionary attack with a high thread count to speed up the process.

    Why it's wrong here

    Using a high thread count increases the rate of authentication attempts, which can trigger lockouts even if spread across accounts. Hydra can perform password spraying, but high concurrency is dangerous. The scenario emphasizes avoiding lockouts, so a high thread count is counterproductive. This option overlooks the need for rate limiting and careful timing.

  • ✗

    Spray each password against a small subset of usernames, then rotate to another subset without waiting.

    Why it's wrong here

    Rotating subsets without waiting can still accumulate failed attempts per account if the same account is targeted multiple times within the lockout observation window. The lockout counter is per account, so any repeated attempts within the window risk lockout. Waiting between rounds is essential. This option does not adequately address the timing requirement to avoid lockouts.

  • ✓

    Spray one password against all usernames, then wait 30 minutes before trying the next password.

    Why this is correct

    Password spraying involves trying a single password against many accounts to avoid lockouts. Waiting between attempts (e.g., 30 minutes) ensures that the account lockout threshold is not triggered, as most lockout policies count failed attempts within a time window. This approach balances efficiency and stealth, directly addressing the scenario's goal of avoiding lockouts while testing common passwords.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.