
Offensive Security Certified Professional
Master the art of penetration testing with the industry-standard OSCP certification, focusing on hands-on exploitation, vulnerability assessment, and advanced Active Directory attack methodologies.
Exam syllabus, organized by domain
Try a real question
Sample Offensive Security Certified Professional exam question
Answer this question the same way you would on exam day. No sign-up needed — one random question, three tries to swap it out.
In a penetration test, an automated scan finds no vulnerability in a PHP application where the 'template' parameter is used unsafely in an include operation. You suspect an LFI-to-RCE chain that can give you a foothold as the web server user, after which local privilege escalation is required. Which approach best reflects manual verification, contextual payload selection, and the OSCP mindset?
Frequently asked questions
Key facts about the Offensive Security Certified Professional certification and how to prepare for it.
Skills & Requirements
What you need to know before attempting the Offensive Security Certified Professional exam.
Compare related certifications
Explore other certifications in the same category and see how they stack up.
Related articles
Learn more about Cybersecurity with these guides.

ISC2 CC 'Best/Most' Questions: Why Memorization Fails and How to Think Like the Exam
Stop memorizing facts and start applying logic. Learn the decision framework to solve ISC2 CC scenario questions and eliminate distractors effectively.

CISSP 'Best Answer' Traps: Mastering the Stem Qualifier Before Exam Day
Stop falling for plausible distractors. Learn how to decode 'first,' 'best,' and 'most' to navigate the CISSP CAT exam's decision logic.
