PEN-200 Password Attacks Practice Question
You are conducting a password spraying attack against an Active Directory environment. You have a list of common passwords and a list of usernames. To avoid locking out accounts, which approach should you take?
⚠ Common exam trap
Watch out — candidates often confuse password spraying with brute-forcing, leading to techniques that concentrate attempts on few accounts and trigger lockouts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spray one password against all usernames, then wait 30 minutes before trying the next password.
Password spraying avoids lockouts by trying a single password against many accounts, then waiting before the next password. This keeps the number of failed attempts per account below the lockout threshold within the observation window. Trying all passwords against one account or using high concurrency increases lockout risk. Rotating subsets without waiting can also accumulate attempts. Thus, spraying one password at a time with a delay is the correct approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Try all passwords against one username before moving to the next username.
Why it's wrong here
This is a brute-force attack against a single account, which will quickly trigger account lockout if the lockout threshold is low. It does not spread attempts across accounts and is likely to lock the targeted account. This approach is inefficient and risky in a typical AD environment with lockout policies. It contradicts the goal of avoiding lockouts.
- ✗
Use a tool like Hydra to perform a dictionary attack with a high thread count to speed up the process.
Why it's wrong here
Using a high thread count increases the rate of authentication attempts, which can trigger lockouts even if spread across accounts. Hydra can perform password spraying, but high concurrency is dangerous. The scenario emphasizes avoiding lockouts, so a high thread count is counterproductive. This option overlooks the need for rate limiting and careful timing.
- ✗
Spray each password against a small subset of usernames, then rotate to another subset without waiting.
Why it's wrong here
Rotating subsets without waiting can still accumulate failed attempts per account if the same account is targeted multiple times within the lockout observation window. The lockout counter is per account, so any repeated attempts within the window risk lockout. Waiting between rounds is essential. This option does not adequately address the timing requirement to avoid lockouts.
- ✓
Spray one password against all usernames, then wait 30 minutes before trying the next password.
Why this is correct
Password spraying involves trying a single password against many accounts to avoid lockouts. Waiting between attempts (e.g., 30 minutes) ensures that the account lockout threshold is not triggered, as most lockout policies count failed attempts within a time window. This approach balances efficiency and stealth, directly addressing the scenario's goal of avoiding lockouts while testing common passwords.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.