OSCP Offensive Security Certified Professional Practice Test

140 questions available

Build your confidence for OSCP Offensive Security Certified Professional. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
24 hours Time Limit
Professional Level
Your practice
140 Practice questions
2 hours 20 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 70 Published passing score for this certification.
Explore exam topics Official objectives from OffSec
OffSec140 practice questionsBank updated 2026-07-24
Blueprint verifiedChecked against OffSec official objectivesMetadata verified 2026-09-26How we verify

Exam overview and details

The Offensive Security Certified Professional (OSCP) certification is the industry's premier, performance-based penetration testing credential. Awarded by Offensive Security, it validates a practitioner's ability to methodically identify, exploit, and document security vulnerabilities in a controlled environment. Unlike multiple-choice exams, the OSCP is a rigorous 24-hour hands-on test where candidates must successfully compromise a series of target machines and produce a comprehensive penetration test report. This certification is globally recognized as a benchmark for practical offensive security skills, covering essential methodologies, tools, and techniques used in real-world penetration testing engagements. Earning the OSCP demonstrates not just theoretical knowledge, but proven competence in performing security assessments, making it one of the most respected and sought-after credentials for security professionals seeking to advance in red teaming, penetration testing, and vulnerability assessment roles.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Linux Privilege Escalation

sudo -l output for the current user shows: "(root) NOPASSWD: /usr/bin/find". You want to escalate to a root shell. Which technique is canonical for this configuration, and which resource catalogs the exact command syntax?

Linux Privilege Escalation

On a low-privileged user's home directory you find an unencrypted ~/.ssh/id_rsa with restrictive permissions plus several public keys in ~/.ssh/authorized_keys for OTHER hosts in scope. Why are these credentials high-value, and what should the operator do next?

Information Gathering

An authorized internal Nmap scan of /24 returns 22 hosts. On three of them you find: (Host A) TCP/445 SMB and TCP/3389 RDP, (Host B) TCP/80 HTTP custom application and TCP/22 SSH, (Host C) TCP/389 LDAP, TCP/88 Kerberos, TCP/445 SMB, and TCP/636 LDAPS. Given an OSCP-style time-boxed engagement, which host is the highest-value first enumeration target and why?

Active Directory Attacks

You discover that the AD CS Web Enrollment role is installed and reachable over HTTP without channel binding or Extended Protection for Authentication (EPA). Which abuse case (ADCS ESC#) does this enable, and what is the canonical chain to leverage it from a non-privileged operator position?

Common Web Application Attacks

You identify a Java application accepting serialized objects via HTTP cookies (the cookie value starts with "rO0AB" -- base64 for the Java serialization magic bytes). What attack class does this enable, and what tool generates payloads against common Java gadget-chain libraries?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

The OSCP matters because it provides an objective, performance-based validation of practical offensive security skills that are directly applicable to real-world scenarios. In an industry flooded with theoretical certifications, the OSCP stands apart by proving a candidate can actually execute attacks, pivot through networks, and document findings professionally. This hands-on proof of competency is highly valued by employers, often serving as a key differentiator for roles in penetration testing, red teaming, and security consulting. It signifies a practitioner's perseverance, problem-solving ability, and deep understanding of exploitation techniques, leading to significant career advancement, increased earning potential, and immediate industry recognition among peers and hiring managers.

These are the backgrounds the certifying body suggests. Check the vendor's own page for anything it formally requires.

What this exam covers

01Active Directory Introduction and Enumeration

02Advanced Tunneling

03Antivirus Evasion

04Assembling the Pieces

05Attacking Active Directory Authentication

06Client-Side Attacks

07Common Web Application Attacks

08Effective Learning Strategies

09Fixing Exploits

10Information Gathering

11Introduction to Cybersecurity

12Introduction to Web Applications

13Lateral Movement in Active Directory

14Linux Privilege Escalation

15Locating Public Exploits

16Password Attacks

17Penetration Testing with Kali Linux : General Course Introduction

18Port Redirection and SSH Tunneling

19Report Writing for Penetration Testers

20SQL Injection Attacks

21The Metasploit Framework

22The OSCP Exam Information

23Trying Harder: The Labs

24Vulnerability Scanning

25Windows Privilege Escalation

Exam Details OSCP | $1499 USD | 24 hours

Exam Code OSCP
Vendor OffSec
Exam Cost $1499 USD
Passing Score 70
Time Limit 24 hours
Question TypesPractical/Hands-On (exploit vulnerable machines, submit proof.txt files)
Retake Policy Retake attempts can be purchased separately. No mandatory waiting period. Retake pricing varies by course bundle.
Exam Format Practical / Penetration Test Lab
Online Proctoring Available
Available In
English

Frequently Asked Questions

What is the format of the OSCP exam, and how is it scored?

What are the prerequisites for attempting the OSCP certification?

How does the OSCP differ from other penetration testing certifications?

What is the value of the PWK lab time, and how should I use it effectively?

What career paths typically value or require the OSCP certification?