Courseiva
Password Attacks →mediumMultiple Select

PEN-200 Password Attacks Practice Question

You are performing a password spraying attack against an Active Directory environment. To avoid locking out accounts, which TWO of the following practices should you follow? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse password spraying with brute-forcing, leading to the selection of practices that actually increase lockout risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a single password attempt per account per lockout window.

Password spraying avoids lockouts by limiting attempts per account. Using a single attempt per lockout window and monitoring the lockout policy are both critical. Attempting multiple passwords per account or using large password lists increases lockout risk. Targeting only never-logged-in accounts is irrelevant to lockout avoidance. Thus, the correct practices are to use one attempt per window and to monitor the policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a large list of common passwords for each account.

    Why it's wrong here

    Using a large list of passwords per account is essentially brute-forcing and will quickly lock accounts if the lockout threshold is low. Password spraying uses a small set of passwords (often just one) across many accounts. This approach is not suitable for avoiding lockouts.

  • ✗

    Attempt multiple passwords per account in quick succession.

    Why it's wrong here

    Attempting multiple passwords per account in quick succession is a brute-force approach that will likely trigger account lockouts. Password spraying specifically avoids this by using few attempts per account. This practice is contrary to the goal of avoiding lockouts.

  • ✓

    Use a single password attempt per account per lockout window.

    Why this is correct

    Password spraying aims to avoid lockouts by trying one password against many accounts, then waiting before trying another password. Using a single attempt per account per lockout window respects the lockout threshold, minimizing the risk of locking accounts. This is a core principle of password spraying.

  • ✗

    Target only accounts that have never logged in.

    Why it's wrong here

    Targeting only accounts that have never logged in is not a reliable strategy; such accounts might still have lockout policies, and they may be service accounts with complex passwords. Moreover, this does not address the core need to avoid lockouts through careful attempt management.

  • ✓

    Monitor the domain's lockout policy and adjust attempts accordingly.

    Why this is correct

    Understanding the lockout policy—such as threshold and duration—is essential to calibrate the spraying attack. By monitoring the policy, you can set a safe number of attempts and delay between rounds, ensuring you do not exceed the threshold. This is a best practice for successful password spraying.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.