OSWE Offensive Security Web Expert Practice Test

193 questions available

Build your confidence for OSWE Offensive Security Web Expert. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
24 hours Time Limit
Expert Level
Your practice
193 Practice questions
3 hours 13 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 85 Published passing score for this certification.
Official objectives from OffSec
OffSec193 practice questionsBank updated 2026-07-24
Blueprint verifiedChecked against OffSec official objectivesMetadata verified 2026-06-07How we verify

Exam overview and details

The Offensive Security Web Expert (OSWE) certification represents the pinnacle of web application security expertise, validating advanced offensive security skills through rigorous hands-on examination. This elite certification requires candidates to demonstrate sophisticated source code analysis, exploit development, and vulnerability chaining across complex, modern web applications. Unlike entry-level certifications, OSWE focuses on the methodology of discovering novel vulnerabilities in white-box scenarios, emphasizing the ability to read, understand, and weaponize application source code. Successful certification holders prove they can move beyond automated tools and standardized payloads to conduct professional-grade security assessments, identifying logic flaws, business process vulnerabilities, and complex multi-step attack chains that evade conventional testing. The certification is globally recognized as a benchmark for senior application security consultants, penetration testers, and red team operators, signifying a practitioner's ability to perform at an expert level in real-world engagements.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

.NET Web

An ASP.NET Web Forms (.NET Framework 4.8) application leaks `machineKey` from a misconfigured backup. What is the highest-impact exploitation primitive?

SSTI

A Spring Boot 2.7 application uses Thymeleaf with `SpringStandardDialect` and renders a fragment via `model.addAttribute("greeting", request.getParameter("g"))` then ` `. The developer claims this is safe. Where (if anywhere) is the actual SSTI risk in a Spring/Thymeleaf application?

Source Code Review and Authentication Bypass

A code review of CareQueue's template preview feature focuses on sprint 17 code that recently moved from an admin-only route to an API endpoint. In the relevant path, a JWT verifier chooses the verification key from an untrusted header field before it checks issuer and audience. Which review finding should drive the authentication fix?

OS Command Injection

A code review of BeaconCMS's analytics preview feature focuses on sprint 16 code that recently moved from an admin-only route to an API endpoint. In the relevant path, a WebSocket handler passes a client-supplied container name into a shell command used to collect logs. Which change removes the command injection weakness?

Cryptographic Vulnerabilities

Storing user passwords with which algorithm is recommended by OWASP ASVS / NIST 800-63B in 2024?

Exam insights and study advice

The OSWE certification is a definitive career differentiator in the cybersecurity landscape, signaling to employers, clients, and peers that you possess the rare ability to conduct deep, manual web application security assessments. It bridges the gap between theoretical knowledge and practical, expert-level exploitation, a skillset in critical demand as organizations face increasingly sophisticated threats against custom applications. Holding this certification places you among a respected community of experts, often leading to roles such as Senior Application Security Engineer, Principal Penetration Tester, or Security Research Lead. It demonstrates not just technical proficiency, but the analytical mindset, persistence, and methodological rigor required to secure modern software in an era of DevOps and continuous deployment.

These are the backgrounds the certifying body suggests. Check the vendor's own page for anything it formally requires.

What this exam covers

01Cross-Site Scripting (XSS) and Prototype Pollution

02Deserialization Vulnerabilities

03Exploit Chaining and Report Writing

04OS Command Injection

05Server-Side Request Forgery (SSRF)

06Source Code Review and Authentication Bypass

07SQL Injection via Source Code Analysis

08XML External Entity (XXE) Injection

Exam Details OSWE | $1499 USD | 24 hours

Exam Code OSWE
Vendor OffSec
Exam Cost $1499 USD
Passing Score 85
Time Limit 24 hours
Question TypesPractical/Hands-On (exploit vulnerable machines, submit proof.txt files)
Retake Policy Retake attempts can be purchased separately. No mandatory waiting period. Retake pricing varies by course bundle.
Exam Format Practical / Penetration Test Lab
Online Proctoring Available
Available In
English

Frequently Asked Questions

What are the key prerequisites for attempting the OSWE certification?

How does the OSWE exam format differ from other practical security certifications?

What career paths and roles does the OSWE certification best prepare you for?

How is the OSWE viewed within the industry compared to other web security certifications?

What is the recommended preparation strategy for the OSWE exam?