OffSec Exploit Developer (OSED) Practice Test

84 preguntas disponibles

Gana confianza para OffSec Exploit Developer (OSED). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
24 horas Límite de Tiempo
Tu práctica
84 Preguntas de práctica
1 hora 24 minutos Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El listón a superar 75 Puntuación mínima publicada para obtener esta certificación.
Explora los temas del examen Objetivos oficiales de OffSec
OffSec84 preguntas de práctica
Temario verificadoVerificado con OffSec official objectivesMetadatos verificados 2026-06-07Cómo verificamos

Descripción y detalles del examen

The OffSec Exploit Developer (OSED) exam is a rigorous, hands-on assessment of advanced Windows exploit development skills. It tests a candidate's ability to methodically analyze software, identify vulnerabilities, and craft reliable exploits in constrained, realistic environments. The exam focuses on defeating modern exploit mitigations like Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) on 32-bit Windows systems, requiring deep understanding of stack-based overflows, structured exception handler (SEH) overwrites, and Return-Oriented Programming (ROP). Successful candidates demonstrate not just theoretical knowledge, but the practical discipline to reverse engineer binaries, write custom shellcode, and chain techniques to achieve code execution. This exam is designed for penetration testers, red teamers, malware analysts, and security researchers who need to move beyond using public exploits and develop their own capabilities. Passing validates a practitioner's ability to conduct sophisticated offensive security research and handle custom, unknown vulnerabilities.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

WinDbg and x86 Architecture

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. The candidate needs gadget addresses from a module and wants to avoid rebasing surprises. What should the candidate do next?

SEH Overflows

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. A Unicode copy doubles many bytes before they reach the SEH record. What should the candidate do next?

Stack-Based Buffer Overflows

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. A bad-character test shows the payload truncates at 0x00 and later mutates 0x0a. What conclusion fits the evidence?

DEP, ASLR, and ROP Bypass

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. The candidate can leak an address inside a randomized module. What conclusion fits the evidence?

SEH Overflows

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. SEHOP is enabled and the overwritten chain no longer reaches the expected final handler. Which choice preserves reliability?

Oportunidades profesionales y salario

Salario medio: $135,980mercado de EE. UU.– Software Developers

Fuente: BLS Occupational Employment and Wage Statistics, May 2025 -- Software Developers (SOC 15-1252), US national. Occupation median, not a certification salary. (2025)

Software Developers

Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.

Qué temas cubre este examen

01Bypassing DEP and ASLR

02Egg Hunters

03Format String Vulnerabilities

04Return-Oriented Programming (ROP)

05SEH (Structured Exception Handling) Exploits

06Stack-Based Buffer Overflows

07Windows x86 Assembly and Shellcoding

Detalles del Examen OSED | $1499 USD | 24 horas

Código del Examen OSED
Proveedor OffSec
Costo del Examen $1499 USD
Puntaje Mínimo 75
Límite de Tiempo 24 horas
Tipos de PreguntasAún no disponible en este idioma
Política de Repetición Retake attempts can be purchased separately. No mandatory waiting period. Retake pricing varies by course bundle.
Formato del Examen Practical / Penetration Test Lab
Supervisión en Línea Disponible
Disponible En
English

Preguntas Frecuentes

¿Cuánto conocimiento de ensamblaje y ingeniería inversa se requiere realmente?

¿El examen se trata únicamente de escribir shellcode desde cero?

¿Qué tan importante es la gestión del tiempo durante el examen?

¿Puedo confiar en herramientas públicas como Metasploit o compiladores ROP automatizados?

¿Cuál es el mayor cambio de mentalidad necesario de OSCP a OSED?