OffSec Exploit Developer (OSED) Practice Test
Build your confidence for OffSec Exploit Developer (OSED). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.
Try a sample questionExam overview and details
The OffSec Exploit Developer (OSED) exam is a rigorous, hands-on assessment of advanced Windows exploit development skills. It tests a candidate's ability to methodically analyze software, identify vulnerabilities, and craft reliable exploits in constrained, realistic environments. The exam focuses on defeating modern exploit mitigations like Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) on 32-bit Windows systems, requiring deep understanding of stack-based overflows, structured exception handler (SEH) overwrites, and Return-Oriented Programming (ROP). Successful candidates demonstrate not just theoretical knowledge, but the practical discipline to reverse engineer binaries, write custom shellcode, and chain techniques to achieve code execution. This exam is designed for penetration testers, red teamers, malware analysts, and security researchers who need to move beyond using public exploits and develop their own capabilities. Passing validates a practitioner's ability to conduct sophisticated offensive security research and handle custom, unknown vulnerabilities.
Sample Questions
Choose an answer and explore the explanation to see how practice works.
An OSED candidate is reviewing a 32-bit Windows service in WinDbg. The candidate needs gadget addresses from a module and wants to avoid rebasing surprises. What should the candidate do next?
An OSED candidate is reviewing a 32-bit Windows service in WinDbg. A Unicode copy doubles many bytes before they reach the SEH record. What should the candidate do next?
An OSED candidate is reviewing a 32-bit Windows service in WinDbg. A bad-character test shows the payload truncates at 0x00 and later mutates 0x0a. What conclusion fits the evidence?
An OSED candidate is reviewing a 32-bit Windows service in WinDbg. The candidate can leak an address inside a randomized module. What conclusion fits the evidence?
An OSED candidate is reviewing a 32-bit Windows service in WinDbg. SEHOP is enabled and the overwritten chain no longer reaches the expected final handler. Which choice preserves reliability?
Career Opportunities & Salary
Exam insights and study advice
In real-world security assessments, public exploits are often unavailable, patched, or unreliable against customized targets. The ability to independently develop a working exploit from a discovered vulnerability is a critical, high-value skill. It transforms a security finding from a theoretical risk into a demonstrable proof of impact, essential for convincing stakeholders and accurately gauging risk. This skill is fundamental for advanced red team operations, vulnerability research, and developing a deeper understanding of how defenses work and how they can be circumvented, ultimately leading to more resilient systems.
Recommended
These are the backgrounds the certifying body suggests. Check the vendor's own page for anything it formally requires.