OSCP Offensive Security Certified Professional Practice Test

140 preguntas disponibles

Gana confianza para OSCP Offensive Security Certified Professional. Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
24 horas Límite de Tiempo
Professional Nivel
Tu práctica
140 Preguntas de práctica
2 horas 20 minutos Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El listón a superar 70 Puntuación mínima publicada para obtener esta certificación.
Explora los temas del examen Objetivos oficiales de OffSec
OffSec140 preguntas de prácticaBanco actualizado el 2026-07-24
Temario verificadoVerificado con OffSec official objectivesMetadatos verificados 2026-09-26Cómo verificamos

Descripción y detalles del examen

The Offensive Security Certified Professional (OSCP) certification is the industry's premier, performance-based penetration testing credential. Awarded by Offensive Security, it validates a practitioner's ability to methodically identify, exploit, and document security vulnerabilities in a controlled environment. Unlike multiple-choice exams, the OSCP is a rigorous 24-hour hands-on test where candidates must successfully compromise a series of target machines and produce a comprehensive penetration test report. This certification is globally recognized as a benchmark for practical offensive security skills, covering essential methodologies, tools, and techniques used in real-world penetration testing engagements. Earning the OSCP demonstrates not just theoretical knowledge, but proven competence in performing security assessments, making it one of the most respected and sought-after credentials for security professionals seeking to advance in red teaming, penetration testing, and vulnerability assessment roles.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

Linux Privilege Escalation

sudo -l output for the current user shows: "(root) NOPASSWD: /usr/bin/find". You want to escalate to a root shell. Which technique is canonical for this configuration, and which resource catalogs the exact command syntax?

Linux Privilege Escalation

On a low-privileged user's home directory you find an unencrypted ~/.ssh/id_rsa with restrictive permissions plus several public keys in ~/.ssh/authorized_keys for OTHER hosts in scope. Why are these credentials high-value, and what should the operator do next?

Information Gathering

An authorized internal Nmap scan of /24 returns 22 hosts. On three of them you find: (Host A) TCP/445 SMB and TCP/3389 RDP, (Host B) TCP/80 HTTP custom application and TCP/22 SSH, (Host C) TCP/389 LDAP, TCP/88 Kerberos, TCP/445 SMB, and TCP/636 LDAPS. Given an OSCP-style time-boxed engagement, which host is the highest-value first enumeration target and why?

Active Directory Attacks

You discover that the AD CS Web Enrollment role is installed and reachable over HTTP without channel binding or Extended Protection for Authentication (EPA). Which abuse case (ADCS ESC#) does this enable, and what is the canonical chain to leverage it from a non-privileged operator position?

Common Web Application Attacks

You identify a Java application accepting serialized objects via HTTP cookies (the cookie value starts with "rO0AB" -- base64 for the Java serialization magic bytes). What attack class does this enable, and what tool generates payloads against common Java gadget-chain libraries?

Oportunidades profesionales y salario

Salario medio: $129,180mercado de EE. UU.– Information Security Analysts

Fuente: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.

Qué temas cubre este examen

01Active Directory Introduction and Enumeration

02Advanced Tunneling

03Antivirus Evasion

04Assembling the Pieces

05Attacking Active Directory Authentication

06Client-Side Attacks

07Common Web Application Attacks

08Effective Learning Strategies

09Fixing Exploits

10Information Gathering

11Introduction to Cybersecurity

12Introduction to Web Applications

13Lateral Movement in Active Directory

14Linux Privilege Escalation

15Locating Public Exploits

16Password Attacks

17Penetration Testing with Kali Linux : General Course Introduction

18Port Redirection and SSH Tunneling

19Report Writing for Penetration Testers

20SQL Injection Attacks

21The Metasploit Framework

22The OSCP Exam Information

23Trying Harder: The Labs

24Vulnerability Scanning

25Windows Privilege Escalation

Detalles del Examen OSCP | $1499 USD | 24 horas

Código del Examen OSCP
Proveedor OffSec
Costo del Examen $1499 USD
Puntaje Mínimo 70
Límite de Tiempo 24 horas
Tipos de PreguntasAún no disponible en este idioma
Política de Repetición Retake attempts can be purchased separately. No mandatory waiting period. Retake pricing varies by course bundle.
Formato del Examen Practical / Penetration Test Lab
Supervisión en Línea Disponible
Disponible En
English

Preguntas Frecuentes

¿Cuál es el formato del examen OSCP y cómo se califica?

¿Cuáles son los requisitos previos para intentar la certificación OSCP?

¿En qué se diferencia el OSCP de otras certificaciones de pruebas de penetración?

¿Cuál es el valor del tiempo en el laboratorio PWK y cómo debo utilizarlo de manera efectiva?

¿Qué trayectorias profesionales valoran o requieren típicamente la certificación OSCP?