CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester wants to test the strength of an organization's Active Directory credentials without triggering account lockout policies. The tester decides to try a small number of common passwords, such as 'Winter2024!', against every enabled user account in the domain. Which technique is the tester performing?

  1. ACredential stuffing
  2. BKerberoasting
  3. CPassword spraying
  4. DDictionary attack
Show answer & explanation

Correct answer: C. Password spraying

Password spraying tests one or a few passwords against many accounts, spreading attempts across the user base to stay under per-account lockout thresholds, unlike a dictionary attack which tries many passwords against a single account.

Why the other options are wrong

  • A. Credential stuffing uses previously breached username/password pairs, not a single guessed password.
  • B. Kerberoasting targets service account tickets, not password guessing.
  • D. A dictionary attack tries many passwords against one account, the opposite approach.

Password Spraying

An authentication attack that tries a small set of common passwords against many user accounts to avoid triggering lockout policies.

  • Low-and-slow approach across many accounts
  • Avoids per-account lockout thresholds
  • Often targets seasonal or default passwords

Memory trick: Spray wide, not deep — one password, many doors.

More Attacks and Exploits questions