CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A penetration tester wants to test the strength of an organization's Active Directory credentials without triggering account lockout policies. The tester decides to try a small number of common passwords, such as 'Winter2024!', against every enabled user account in the domain. Which technique is the tester performing?
- ACredential stuffing
- BKerberoasting
- CPassword spraying
- DDictionary attack
Show answer & explanationAnswer & explanation
Correct answer: C. Password spraying
Password spraying tests one or a few passwords against many accounts, spreading attempts across the user base to stay under per-account lockout thresholds, unlike a dictionary attack which tries many passwords against a single account.
Why the other options are wrong
- A. Credential stuffing uses previously breached username/password pairs, not a single guessed password.
- B. Kerberoasting targets service account tickets, not password guessing.
- D. A dictionary attack tries many passwords against one account, the opposite approach.
Password Spraying
An authentication attack that tries a small set of common passwords against many user accounts to avoid triggering lockout policies.
- Low-and-slow approach across many accounts
- Avoids per-account lockout thresholds
- Often targets seasonal or default passwords
Memory trick: Spray wide, not deep — one password, many doors.