An unhandled error has occurred. Reload X
Skip to main content

BSCP: Burp Suite Certified Practitioner Exam Practice Test

140 questions available

The Burp Suite Certified Practitioner (BSCP) is an elite, performance-based certification from PortSwigger that validates advanced, hands-on proficiency in web application security testing using Burp Suite Professional. Unlike theoretical exams, the BSCP requires candidates to demonstrate practical exploitation skills against realistic, modern web application vulnerabilities in a controlled environment. This certification is widely regarded as the industry benchmark for offensive web security expertise, testing abilities across the full spectrum of the OWASP Top Ten and beyond, including business logic flaws, complex access control bypasses, and chained attack vectors. Earning the BSCP signifies not just knowledge of tools, but the methodological rigor, creative problem-solving, and deep technical understanding required to identify and exploit security weaknesses that automated scanners miss. It is designed for penetration testers, red teamers, and application security specialists seeking to prove their capability in real-world assessment scenarios.

Certification exam
Foundational Level
Practice bank
140 Practice Questions
2 hours 20 minutes Practice Time
Start Practice
The bank 140 Practice questions checked against the official objectives.
qf-import140 practice questionsBlueprint 1.0Bank updated 2026-05-04

Sample Questions

Try a few questions to see what the full exam is like.

Burp Suite Pro Tools & Workflow

Target scope is configured in Burp to:

Advanced Topics & Tool Extensions

Writing a Burp extension in Java vs Python relies on:

OWASP Top 10 Web Vulnerabilities

OAuth implicit flow returning access tokens in the URL fragment is discouraged because:

Burp Suite Pro Tools & Workflow

A macro in Burp captures a sequence of requests that should be replayed as a unit, most commonly to:

Advanced Topics & Tool Extensions

HTTP/2 downgrade smuggling exploits:

Why This Certification Opens Doors

The BSCP matters because it provides unambiguous, vendor-backed proof of practical skill in a field where theoretical knowledge is insufficient. It is highly respected by employers and peers alike, often serving as a key differentiator for senior and principal-level roles in penetration testing and application security. Holding this certification demonstrates a practitioner's ability to handle complex, modern web applications and directly correlates with the high-value, hands-on work that drives security improvements. It accelerates career advancement by establishing credibility, commanding industry recognition, and validating the expertise necessary to lead security assessments and mentor junior team members.

Exam Blueprint

01Access Control and Authorization
02Advanced Tooling and Automation
03API and Web Service Testing
04Authentication and Session Management
05Business Logic Vulnerabilities
06Client-Side Vulnerabilities
07Server-Side Vulnerabilities

Exam Details BSCP

Exam Code BSCP
Vendor qf-import

Frequently Asked Questions

What is the format of the BSCP exam, and how is it proctored?

The BSCP is a 100% practical, online proctored exam. Candidates are given remote access to a dedicated, vulnerable lab environment and must use Burp Suite Professional to find and exploit a series of discrete vulnerabilities within a 4-hour time limit. The exam is proctored via video, audio, and screen sharing to ensure integrity. Passing requires successfully demonstrating exploitation, often by retrieving a specific secret or achieving a defined objective for each challenge.

What level of experience is recommended before attempting the BSCP?

PortSwigger recommends at least 2-3 years of hands-on web application penetration testing experience. Candidates should be thoroughly proficient with Burp Suite Professional's core tools (Proxy, Repeater, Intruder, Scanner) and possess a deep understanding of HTTP/S, web technologies (HTML, JavaScript, APIs), common vulnerability classes (SQLi, XSS, SSRF, XXE, etc.), and authentication/authorization mechanisms. Experience bypassing common filters and WAFs is also crucial.

How does the BSCP differ from other web security certifications like the OSWE?

While both are advanced practical certifications, the BSCP is specifically focused on mastery of the Burp Suite ecosystem and real-time exploitation of live applications. The OSWE (Offensive Security Web Expert) focuses more on white-box source code review and custom exploit development. The BSCP emphasizes the tactical, black-box/brown-box methodology of a professional penetration tester using industry-standard tooling, making it highly complementary to the OSWE's more developer-centric approach.

Are there any official training or preparation resources from PortSwigger?

Yes. PortSwigger provides the definitive preparation path through the 'Burp Suite Certified Practitioner' learning path on the Web Security Academy. This free resource includes over 100 interactive labs covering every topic in the exam blueprint, from foundational to expert level. Successfully completing all labs, especially the 'Expert' and 'Practitioner' tier labs, is considered essential preparation. No official instructor-led training is offered; the exam tests self-directed learning and skill application.

What is the exam retake policy?

If a candidate does not pass, they must wait 30 days before attempting the exam again. A maximum of three attempts are allowed within a 12-month period. Each attempt requires purchasing a new exam voucher. This policy underscores the exam's difficulty and encourages substantial additional preparation between attempts.