An unhandled error has occurred. Reload X
View official blueprint on Cert Atlas

OSCP Offensive Security Certified Professional Practice Test

140 questions available

The Offensive Security Certified Professional (OSCP) certification is the industry's premier, performance-based penetration testing credential. Awarded by Offensive Security, it validates a practitioner's ability to methodically identify, exploit, and document security vulnerabilities in a controlled environment. Unlike multiple-choice exams, the OSCP is a rigorous 24-hour hands-on test where candidates must successfully compromise a series of target machines and produce a comprehensive penetration test report. This certification is globally recognized as a benchmark for practical offensive security skills, covering essential methodologies, tools, and techniques used in real-world penetration testing engagements. Earning the OSCP demonstrates not just theoretical knowledge, but proven competence in performing security assessments, making it one of the most respected and sought-after credentials for security professionals seeking to advance in red teaming, penetration testing, and vulnerability assessment roles.

Certification exam
Professional Level
Career Opportunities & Salary
Entry – Security Tester $80,000 - $121,000
Mid-Career – Penetration Tester $113,000 - $172,000
Senior – Principal Penetration Tester $147,000 - $224,000
Security TesterPenetration TesterPrincipal Penetration Testergrowing market
Why This Certification Opens Doors

The OSCP matters because it provides an objective, performance-based validation of practical offensive security skills that are directly applicable to real-world scenarios. In an industry flooded with theoretical certifications, the OSCP stands apart by proving a candidate can actually execute attacks, pivot through networks, and document findings professionally. This hands-on proof of competency is highly valued by employers, often serving as a key differentiator for roles in penetration testing, red teaming, and security consulting. It signifies a practitioner's perseverance, problem-solving ability, and deep understanding of exploitation techniques, leading to significant career advancement, increased earning potential, and immediate industry recognition among peers and hiring managers.

Exam Blueprint
01Active Directory Enumeration and AttacksEnumerate AD (PowerShell, BloodHound), Kerberos attacks (Kerberoasting, Silver/Golden tickets, AS-REP roasting), Lateral movement (WMI, WinRM, PsExec, Pass-the-Hash)
02Antivirus EvasionAV detection engines, Manual and automated AV evasion
03Assembling the PiecesEnumerate and attack a public network, Pivot into an internal network, Chain to compromise a domain controller
04Client-Side AttacksTarget reconnaissance and client fingerprinting, Office macros and library files, Windows shortcut abuse
05Information GatheringPassive information gathering (OSINT, DNS), Active information gathering (port scanning, SMB/SMTP/SNMP enumeration)
06Linux Privilege EscalationEnumerate Linux permissions and system trails, Abuse cron jobs, SUID, capabilities, sudo, and kernel vulnerabilities
07Locating and Fixing Public ExploitsFind exploits (SearchSploit), Analyze and safely execute public exploits, Fix memory corruption and web exploits
08Password AttacksAttack SSH, RDP, HTTP POST logins, Crack passwords with wordlists and rules, Obtain, crack, pass, and relay NTLM hashes
09Port Redirection and TunnelingPort forwarding with Socat and Windows tools, SSH local/dynamic/remote forwarding, HTTP and DNS tunneling (Chisel, dnscat)
10Report Writing for Penetration TestersNote-taking and documentation structure, Write technical penetration testing reports
11SQL Injection AttacksManual UNION, error-based, and blind SQL injection, SQLmap, MSSQL xp_cmdshell
12The Metasploit FrameworkAuxiliary and exploit modules, Meterpreter and post-exploitation, Pivoting and resource scripts
13Vulnerability ScanningVulnerability scanning theory, Nessus, Nmap Scripting Engine
14Web Application AttacksWeb assessment methodology and OWASP Top 10, Burp Suite, XSS, directory traversal, file inclusion, file upload, command injection
15Windows Privilege EscalationEnumerate Windows privileges and access control, Hijack service binaries and DLLs, Abuse scheduled tasks
Exam Details OSCP
Exam Code OSCP
Vendor OffSec
Exam Format Practical / Penetration Test Lab
Online Proctoring Available
Available In
English
Study Resources
OffSec Learning Library (PEN-200/WEB-300/EXP-301)
OffSecFree
Course material, lab time, and one exam attempt typically bundled together
View
Frequently Asked Questions

What is the format of the OSCP exam, and how is it scored?

The OSCP exam is a 24-hour, proctored, hands-on penetration test in a isolated lab environment. Candidates must compromise a set of target machines, each assigned a point value based on difficulty (typically ranging from 10 to 25 points). A minimum of 70 points is required to pass. The exam is immediately followed by a 24-hour period to submit a comprehensive penetration test report detailing the steps taken, proofs of compromise, and findings. Scoring is based solely on the successful exploitation of targets and the quality of the submitted report.

What are the prerequisites for attempting the OSCP certification?

Offensive Security recommends a solid understanding of networking, Linux and Windows administration, basic scripting or programming (e.g., Bash, Python), and familiarity with core security concepts. While there are no formal mandatory prerequisites, most successful candidates have prior experience in IT or cybersecurity fundamentals. The Penetration Testing with Kali Linux (PWK) course, which includes lab access, is the primary training path and is strongly recommended to build the necessary skills for the exam.

How does the OSCP differ from other penetration testing certifications?

The OSCP is distinguished by its 100% practical, performance-based examination. Unlike certifications that rely on multiple-choice questions or simulated environments, the OSCP requires candidates to perform actual attacks against real, vulnerable systems. This proves an ability to apply tools and techniques creatively and methodically. It is often considered a 'rite of passage' that tests grit and problem-solving under time pressure, whereas other certifications may focus more on knowledge recall or specific tool proficiency.

What is the value of the PWK lab time, and how should I use it effectively?

The PWK lab is a critical component of OSCP preparation, providing a simulated network with hundreds of vulnerable machines of increasing complexity. Effective use involves: 1) Thoroughly working through the course exercises, 2) Attempting to compromise as many lab machines as possible independently, 3) Documenting every step, command, and technique in detail, 4) Researching and experimenting with different exploitation paths, and 5) Focusing on understanding the underlying vulnerability concepts rather than just achieving root/administrator access. The lab builds the methodology and persistence required for the exam.

What career paths typically value or require the OSCP certification?

The OSCP is highly valued for roles including Penetration Tester, Vulnerability Analyst, Security Consultant (Offensive Security), Red Team Member, and Application Security Specialist. It is frequently listed as a preferred or required qualification in job postings for hands-on offensive security positions across consulting firms, MSSPs, financial institutions, and technology companies. It serves as a key credential for advancing into senior technical or team lead positions within penetration testing disciplines.

Reviews & Ratings
No reviews yet

Be the first to review this exam and help other learners!


Share Your Experience