Practice questions · Cybersecurity

Offensive Security Certified Professional (OSCP): Practice Questions

expert 30 questions

Original concept-check questions for the OSCP (Offensive Security Certified Professional). The real exam is hands-on; these are concept checks on the underlying skills behind the PEN-200 course: enumeration, exploitation, privilege escalation, Active Directory, tunnelling and more. Each answer is explained, including why the others are wrong. Filter by domain or difficulty. These are concept checks, not real exam questions, and contain no operational attack instructions.

By The Exam Atlas Editorial Team · Verified 2026-06-06 · ~38 min

  1. Enumeration easy

    On most OSCP targets, the step that unlocks the most progress is:

  2. Enumeration easy

    What is the purpose of enumeration in a penetration test?

  3. Enumeration medium

    An open port discovered during enumeration most directly indicates that:

  4. Enumeration medium

    Service version detection during enumeration is useful mainly because it helps you:

  5. Exploitation easy

    In a penetration test, 'exploitation' refers to:

  6. Exploitation medium

    Why is enumerating a service thoroughly important before attempting to exploit it?

  7. Exploitation medium

    A 'proof of concept' in an exploitation context is best described as:

  8. Exploitation hard

    Why is publicly available exploit code often modified before use in a lab engagement?

  9. Web application attacks medium

    SQL injection is possible when a web application:

  10. Web application attacks medium

    Cross-site scripting (XSS) involves:

  11. Web application attacks hard

    A directory-traversal weakness allows an attacker to:

  12. Web application attacks medium

    The most reliable defence against SQL injection is:

  13. Client-side attacks medium

    Client-side attacks differ from server-side attacks in that they:

  14. Client-side attacks medium

    A common defensive control that reduces the impact of client-side attacks is:

  15. Client-side attacks hard

    Why are client-side attacks relevant even when a network has a strong perimeter firewall?

  16. Privilege escalation easy

    Privilege escalation means:

  17. Privilege escalation medium

    Local privilege escalation differs from initial access because it assumes the operator:

  18. Privilege escalation medium

    On the OSCP exam, why is privilege escalation practice on both Linux and Windows important?

  19. Privilege escalation hard

    A conceptual reason misconfigured file permissions can enable privilege escalation is that:

  20. Active Directory attacks easy

    Active Directory (AD) is best described as:

  21. Active Directory attacks medium

    On the OSCP exam, the Active Directory set is worth:

  22. Active Directory attacks medium

    The OSCP Active Directory portion uses an 'assumed compromise' model, meaning you:

  23. Active Directory attacks hard

    Why does lateral movement matter when working through an Active Directory environment?

  24. Port forwarding & tunnelling medium

    Pivoting in a penetration test refers to:

  25. Port forwarding & tunnelling medium

    Port forwarding is used in an engagement primarily to:

  26. Port forwarding & tunnelling hard

    Tunnelling is most useful when you need to:

  27. Port forwarding & tunnelling hard

    Why are pivoting and tunnelling especially relevant to the OSCP Active Directory set?

  28. Metasploit medium

    Within the OSCP exam, the use of Metasploit is:

  29. Metasploit easy

    Metasploit is best described as:

  30. Metasploit hard

    Why is it valuable to understand manual techniques rather than relying only on an automated framework like Metasploit for OSCP?

Practice questions FAQ

Are these real OSCP exam questions?
No. These are original study questions written to test understanding. They are not real exam questions, exam dumps, or copied from any provider.
How should I use these practice questions?
Answer each one, read the explanation (including why the wrong options are wrong), and use the per-domain score below to focus your revision on weak areas. Revisit before exam day.
How many questions should I do before the exam?
Enough to score consistently across every domain, alongside full-length practice from official or reputable providers. Understanding why each answer is right matters more than raw volume.
What score means I am ready?
A good signal is consistently scoring around 80% or higher across all domains on questions you have not seen before, and being able to explain why the wrong options are wrong.
Should I use exam dumps?
No. Dumps (real or leaked questions) breach provider policy, can void your certification, and do not build the understanding the exam actually tests.

Sources