OSCP Offensive Security Certified Professional Practice Test
Build your confidence for OSCP Offensive Security Certified Professional. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.
Try a sample questionExam overview and details
The Offensive Security Certified Professional (OSCP) certification is the industry's premier, performance-based penetration testing credential. Awarded by Offensive Security, it validates a practitioner's ability to methodically identify, exploit, and document security vulnerabilities in a controlled environment. Unlike multiple-choice exams, the OSCP is a rigorous 24-hour hands-on test where candidates must successfully compromise a series of target machines and produce a comprehensive penetration test report. This certification is globally recognized as a benchmark for practical offensive security skills, covering essential methodologies, tools, and techniques used in real-world penetration testing engagements. Earning the OSCP demonstrates not just theoretical knowledge, but proven competence in performing security assessments, making it one of the most respected and sought-after credentials for security professionals seeking to advance in red teaming, penetration testing, and vulnerability assessment roles.
Sample Questions
Choose an answer and explore the explanation to see how practice works.
sudo -l output for the current user shows: "(root) NOPASSWD: /usr/bin/find". You want to escalate to a root shell. Which technique is canonical for this configuration, and which resource catalogs the exact command syntax?
On a low-privileged user's home directory you find an unencrypted ~/.ssh/id_rsa with restrictive permissions plus several public keys in ~/.ssh/authorized_keys for OTHER hosts in scope. Why are these credentials high-value, and what should the operator do next?
An authorized internal Nmap scan of /24 returns 22 hosts. On three of them you find: (Host A) TCP/445 SMB and TCP/3389 RDP, (Host B) TCP/80 HTTP custom application and TCP/22 SSH, (Host C) TCP/389 LDAP, TCP/88 Kerberos, TCP/445 SMB, and TCP/636 LDAPS. Given an OSCP-style time-boxed engagement, which host is the highest-value first enumeration target and why?
You discover that the AD CS Web Enrollment role is installed and reachable over HTTP without channel binding or Extended Protection for Authentication (EPA). Which abuse case (ADCS ESC#) does this enable, and what is the canonical chain to leverage it from a non-privileged operator position?
You identify a Java application accepting serialized objects via HTTP cookies (the cookie value starts with "rO0AB" -- base64 for the Java serialization magic bytes). What attack class does this enable, and what tool generates payloads against common Java gadget-chain libraries?
Career Opportunities & Salary
Exam insights and study advice
The OSCP matters because it provides an objective, performance-based validation of practical offensive security skills that are directly applicable to real-world scenarios. In an industry flooded with theoretical certifications, the OSCP stands apart by proving a candidate can actually execute attacks, pivot through networks, and document findings professionally. This hands-on proof of competency is highly valued by employers, often serving as a key differentiator for roles in penetration testing, red teaming, and security consulting. It signifies a practitioner's perseverance, problem-solving ability, and deep understanding of exploitation techniques, leading to significant career advancement, increased earning potential, and immediate industry recognition among peers and hiring managers.
Recommended
These are the backgrounds the certifying body suggests. Check the vendor's own page for anything it formally requires.