PEN-200 Password Attacks Practice Question
You are performing a password spraying attack against an Active Directory environment. To avoid locking out accounts, which TWO of the following practices should you follow? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse password spraying with brute-forcing, leading to the selection of practices that actually increase lockout risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a single password attempt per account per lockout window.
Password spraying avoids lockouts by limiting attempts per account. Using a single attempt per lockout window and monitoring the lockout policy are both critical. Attempting multiple passwords per account or using large password lists increases lockout risk. Targeting only never-logged-in accounts is irrelevant to lockout avoidance. Thus, the correct practices are to use one attempt per window and to monitor the policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a large list of common passwords for each account.
Why it's wrong here
Using a large list of passwords per account is essentially brute-forcing and will quickly lock accounts if the lockout threshold is low. Password spraying uses a small set of passwords (often just one) across many accounts. This approach is not suitable for avoiding lockouts.
- ✗
Attempt multiple passwords per account in quick succession.
Why it's wrong here
Attempting multiple passwords per account in quick succession is a brute-force approach that will likely trigger account lockouts. Password spraying specifically avoids this by using few attempts per account. This practice is contrary to the goal of avoiding lockouts.
- ✓
Use a single password attempt per account per lockout window.
Why this is correct
Password spraying aims to avoid lockouts by trying one password against many accounts, then waiting before trying another password. Using a single attempt per account per lockout window respects the lockout threshold, minimizing the risk of locking accounts. This is a core principle of password spraying.
- ✗
Target only accounts that have never logged in.
Why it's wrong here
Targeting only accounts that have never logged in is not a reliable strategy; such accounts might still have lockout policies, and they may be service accounts with complex passwords. Moreover, this does not address the core need to avoid lockouts through careful attempt management.
- ✓
Monitor the domain's lockout policy and adjust attempts accordingly.
Why this is correct
Understanding the lockout policy—such as threshold and duration—is essential to calibrate the spraying attack. By monitoring the policy, you can set a safe number of attempts and delay between rounds, ensuring you do not exceed the threshold. This is a best practice for successful password spraying.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.