Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 2 Question 14 Discussion

According to the MITRE ATT&CK framework, how is the password spraying technique classified?
D) Credential access
A) Privilege escalation
B) Initial access
C) Lateral movement

Cisco 300-220 Exam - Topic 2 Question 14 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 14
Topic #: 2
[All 300-220 Questions]

According to the MITRE ATT&CK framework, how is the password spraying technique classified?

Show Suggested Answer Hide Answer
Suggested Answer: D

The correct answer is Credential Access. In the MITRE ATT&CK framework, password spraying is classified under the Credential Access tactic (TA0006), specifically technique T1110.003 -- Password Spraying. This classification is based on the attacker's primary objective: gaining valid credentials by systematically attempting a small number of common or weak passwords across many user accounts.

Password spraying differs from brute-force attacks in that it intentionally avoids rapid or repeated attempts against a single account, thereby evading account lockout controls and basic detection mechanisms. Instead, attackers ''spray'' one password (for example, Winter2025! or Password123) across a large number of users, exploiting the likelihood that at least one account will use that password.

Although successful password spraying often leads to initial access, MITRE classifies it under Credential Access because the technique's defining action is the acquisition of credentials, not the system entry itself. Initial access is the outcome, while credential theft is the method. This distinction is critical for threat hunters, as it guides where detections and controls should be focused.

From a professional threat hunting perspective, defenders monitor authentication telemetry such as failed and successful logins across identity providers, VPNs, cloud services, and email platforms. Indicators include multiple authentication failures across many accounts from a single source IP, followed by one or more successful logins. Identity-centric logging and anomaly detection are foundational here, reinforcing the principle that identity is the primary attack surface in modern environments.

Understanding password spraying as a credential access technique helps organizations prioritize protections such as strong password policies, MFA enforcement, adaptive authentication, and detection logic tuned for low-and-slow authentication abuse.


Contribute your Thoughts:

0/2000 characters
Jade
4 days ago
It's classified as D) Credential access.
upvoted 0 times
...
Cecil
9 days ago
I’m confused about this one. I thought password spraying was more about gaining initial access, but now I’m second-guessing myself.
upvoted 0 times
...
Josphine
14 days ago
I practiced a similar question, and I think I chose lateral movement for that one. But for this one, I’m leaning towards credential access.
upvoted 0 times
...
Maddie
19 days ago
I remember studying this, and I feel like it might be related to initial access too, but I could be mixing it up with another technique.
upvoted 0 times
...
Edward
24 days ago
I think password spraying falls under credential access, but I’m not entirely sure. It seems to fit that category best.
upvoted 0 times
...

Save Cancel