OffSec Exploit Developer (OSED) Practice Test

84 questions available

Build your confidence for OffSec Exploit Developer (OSED). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
24 hours Time Limit
Your practice
84 Practice questions
1 hour 24 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 75 Published passing score for this certification.
Explore exam topics Official objectives from OffSec
OffSec84 practice questions
Blueprint verifiedChecked against OffSec official objectivesMetadata verified 2026-06-07How we verify

Exam overview and details

The OffSec Exploit Developer (OSED) exam is a rigorous, hands-on assessment of advanced Windows exploit development skills. It tests a candidate's ability to methodically analyze software, identify vulnerabilities, and craft reliable exploits in constrained, realistic environments. The exam focuses on defeating modern exploit mitigations like Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) on 32-bit Windows systems, requiring deep understanding of stack-based overflows, structured exception handler (SEH) overwrites, and Return-Oriented Programming (ROP). Successful candidates demonstrate not just theoretical knowledge, but the practical discipline to reverse engineer binaries, write custom shellcode, and chain techniques to achieve code execution. This exam is designed for penetration testers, red teamers, malware analysts, and security researchers who need to move beyond using public exploits and develop their own capabilities. Passing validates a practitioner's ability to conduct sophisticated offensive security research and handle custom, unknown vulnerabilities.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

WinDbg and x86 Architecture

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. The candidate needs gadget addresses from a module and wants to avoid rebasing surprises. What should the candidate do next?

SEH Overflows

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. A Unicode copy doubles many bytes before they reach the SEH record. What should the candidate do next?

Stack-Based Buffer Overflows

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. A bad-character test shows the payload truncates at 0x00 and later mutates 0x0a. What conclusion fits the evidence?

DEP, ASLR, and ROP Bypass

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. The candidate can leak an address inside a randomized module. What conclusion fits the evidence?

SEH Overflows

An OSED candidate is reviewing a 32-bit Windows service in WinDbg. SEHOP is enabled and the overwritten chain no longer reaches the expected final handler. Which choice preserves reliability?

Career Opportunities & Salary

Median salary: $135,980– Software Developers

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Software Developers (SOC 15-1252), US national. Occupation median, not a certification salary. (2025)

Software Developers

Exam insights and study advice

In real-world security assessments, public exploits are often unavailable, patched, or unreliable against customized targets. The ability to independently develop a working exploit from a discovered vulnerability is a critical, high-value skill. It transforms a security finding from a theoretical risk into a demonstrable proof of impact, essential for convincing stakeholders and accurately gauging risk. This skill is fundamental for advanced red team operations, vulnerability research, and developing a deeper understanding of how defenses work and how they can be circumvented, ultimately leading to more resilient systems.

These are the backgrounds the certifying body suggests. Check the vendor's own page for anything it formally requires.

What this exam covers

01Bypassing DEP and ASLR

02Egg Hunters

03Format String Vulnerabilities

04Return-Oriented Programming (ROP)

05SEH (Structured Exception Handling) Exploits

06Stack-Based Buffer Overflows

07Windows x86 Assembly and Shellcoding

Exam Details OSED | $1499 USD | 24 hours

Exam Code OSED
Vendor OffSec
Exam Cost $1499 USD
Passing Score 75
Time Limit 24 hours
Question TypesPractical/Hands-On (exploit vulnerable machines, submit proof.txt files)
Retake Policy Retake attempts can be purchased separately. No mandatory waiting period. Retake pricing varies by course bundle.
Exam Format Practical / Penetration Test Lab
Online Proctoring Available
Available In
English

Frequently Asked Questions

How much assembly and reverse engineering knowledge is truly required?

Is the exam solely about writing shellcode from scratch?

How important is time management during the exam?

Can I rely on public tools like Metasploit or automated ROP compilers?

What is the biggest shift in mindset needed from OSCP to OSED?