OSCP – OffSec Certified Professional
The real OSCP exam is a fully hands-on, 24-hour practical penetration test, not a multiple-choice exam — this simulator is a concept and methodology check aligned to the PEN-200 syllabus, covering enumeration, exploitation, web application attacks, Active Directory attacks, and privilege escalation, so you can rehearse the underlying knowledge before you get in the lab.
Ready to sit the mock exam?
The timer starts as soon as you begin. You can flag questions, move freely between them, and review everything before submitting. No sign-in required — sign in afterwards to save the result to your history.
Start OSCP examSkills measured
Information Gathering and Enumeration
20%Reconnaissance, port/service scanning, and enumerating hosts, shares, and applications.
Vulnerability Scanning and Exploitation
25%Identifying and exploiting known vulnerabilities, including buffer overflows and public exploits.
Web Application Attacks
20%SQL injection, file inclusion, command injection, and other common web attack vectors.
Active Directory Attacks
20%AD enumeration, Kerberoasting, lateral movement, and domain privilege escalation.
Post-Exploitation, Privilege Escalation, and Reporting
15%Local privilege escalation techniques, pivoting, and professional penetration-test reporting.