OSWE Offensive Security Web Expert Practice Test

193 preguntas disponibles

Gana confianza para OSWE Offensive Security Web Expert. Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
24 horas Límite de Tiempo
Expert Nivel
Tu práctica
193 Preguntas de práctica
3 horas 13 minutos Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El listón a superar 85 Puntuación mínima publicada para obtener esta certificación.
Objetivos oficiales de OffSec
OffSec193 preguntas de prácticaBanco actualizado el 2026-07-24
Temario verificadoVerificado con OffSec official objectivesMetadatos verificados 2026-06-07Cómo verificamos

Descripción y detalles del examen

The Offensive Security Web Expert (OSWE) certification represents the pinnacle of web application security expertise, validating advanced offensive security skills through rigorous hands-on examination. This elite certification requires candidates to demonstrate sophisticated source code analysis, exploit development, and vulnerability chaining across complex, modern web applications. Unlike entry-level certifications, OSWE focuses on the methodology of discovering novel vulnerabilities in white-box scenarios, emphasizing the ability to read, understand, and weaponize application source code. Successful certification holders prove they can move beyond automated tools and standardized payloads to conduct professional-grade security assessments, identifying logic flaws, business process vulnerabilities, and complex multi-step attack chains that evade conventional testing. The certification is globally recognized as a benchmark for senior application security consultants, penetration testers, and red team operators, signifying a practitioner's ability to perform at an expert level in real-world engagements.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

.NET Web

An ASP.NET Web Forms (.NET Framework 4.8) application leaks `machineKey` from a misconfigured backup. What is the highest-impact exploitation primitive?

SSTI

A Spring Boot 2.7 application uses Thymeleaf with `SpringStandardDialect` and renders a fragment via `model.addAttribute("greeting", request.getParameter("g"))` then ` `. The developer claims this is safe. Where (if anywhere) is the actual SSTI risk in a Spring/Thymeleaf application?

Source Code Review and Authentication Bypass

A code review of CareQueue's template preview feature focuses on sprint 17 code that recently moved from an admin-only route to an API endpoint. In the relevant path, a JWT verifier chooses the verification key from an untrusted header field before it checks issuer and audience. Which review finding should drive the authentication fix?

OS Command Injection

A code review of BeaconCMS's analytics preview feature focuses on sprint 16 code that recently moved from an admin-only route to an API endpoint. In the relevant path, a WebSocket handler passes a client-supplied container name into a shell command used to collect logs. Which change removes the command injection weakness?

Cryptographic Vulnerabilities

Storing user passwords with which algorithm is recommended by OWASP ASVS / NIST 800-63B in 2024?

Qué temas cubre este examen

01Cross-Site Scripting (XSS) and Prototype Pollution

02Deserialization Vulnerabilities

03Exploit Chaining and Report Writing

04OS Command Injection

05Server-Side Request Forgery (SSRF)

06Source Code Review and Authentication Bypass

07SQL Injection via Source Code Analysis

08XML External Entity (XXE) Injection

Detalles del Examen OSWE | $1499 USD | 24 horas

Código del Examen OSWE
Proveedor OffSec
Costo del Examen $1499 USD
Puntaje Mínimo 85
Límite de Tiempo 24 horas
Tipos de PreguntasAún no disponible en este idioma
Política de Repetición Retake attempts can be purchased separately. No mandatory waiting period. Retake pricing varies by course bundle.
Formato del Examen Practical / Penetration Test Lab
Supervisión en Línea Disponible
Disponible En
English

Preguntas Frecuentes

¿Cuáles son los requisitos clave para intentar la certificación OSWE?

¿Cómo difiere el formato del examen OSWE de otras certificaciones de seguridad prácticas?

¿Qué trayectorias profesionales y roles prepara mejor la certificación OSWE?

¿Cómo se ve la OSWE dentro de la industria en comparación con otras certificaciones de seguridad web?

¿Cuál es la estrategia de preparación recomendada para el examen OSWE?