Simulate the real OffSec PEN-200 / OSCP Concepts exam with full-length timed sessions. Questions drawn proportionally from all 11 official blueprint domains — the same mix you'll face on test day.
Simulate real exam conditions
For the most realistic PEN-200 simulation, start a 60 or 120-question session, put away all notes, set a timer matching the real exam duration (90 minutes), and commit to each answer before moving forward. This trains the time management and decision-making skills the real exam tests.
This free PEN-200 mock exam uses the same question distribution as the real OffSec PEN-200 / OSCP Concepts exam. Each session draws questions proportionally from all 11 official blueprint domains published by OffSec, so the topic mix you see accurately reflects what you'll face on test day.
PEN-200 Domain Distribution
Client-Side Attacks
Enumeration and Reconnaissance
Active Directory Attacks
Public Exploits
Web Application Attacks
Linux Privilege Escalation
Buffer Overflow Fundamentals
Port Redirection and Tunneling
Antivirus Evasion
Password Attacks
Windows Privilege Escalation
Every question is checked against the 2026 PEN-200exam objectives and published under the editorial oversight of an engineer with 12+ years' experience. These are original practice questions — not dumps — so you build real understanding rather than memorising answers.
Both the mock exam and practice test use the same question bank. The difference is in how you use them — and when to use each during your PEN-200 study plan.
Practice test — for learning
Use the PEN-200 practice test when you are studying a domain. Answer questions, read every explanation immediately, and build understanding. Do 10–30 questions per domain per session. This is your primary study tool for the first 4 weeks.
Go to practice test →Mock exam — for simulation
Use the PEN-200 mock exam in the final 1–2 weeks before your test date. Complete a 60 or 120-question session without stopping, manage your time, then review all results at the end. This builds exam-day stamina and surfaces final weak spots.
Start 120-question mock →Try these sample questions from the mock exam bank. Commit to an answer before revealing the explanation.
During an authorized penetration test, you want to perform a client-side attack by delivering a malicious HTA file via a phishing email. Which technique is most effective to execute native commands silently when the user opens the file?
Select an answer to reveal the explanation
You are performing a network scan on a target network and notice that ICMP echo requests are blocked, but you need to determine if the target host is alive. Which technique should you utilize to identify active hosts without relying on standard ICMP ping?
Select an answer to reveal the explanation
You have obtained a low-privileged domain user account and are performing internal enumeration. You identify a computer object in the domain where the 'ms-MCS-AdmPwd' attribute is readable by your user account. Which attack path does this vulnerability facilitate?
Select an answer to reveal the explanation
You have identified a vulnerable service using an outdated version of a CMS. You successfully locate a public exploit script on GitHub. What is the most critical first step before running this script against your target?
Select an answer to reveal the explanation
Which of the following describes a successful Path Traversal attack in a web application?
Select an answer to reveal the explanation
You have gained a low-privileged shell on a Linux system and discovered a binary with the SUID bit set. The binary executes a system call to 'cat' without specifying an absolute path. How can you leverage this to escalate privileges?
Select an answer to reveal the explanation
You are analyzing a binary and identify a function that uses strcpy() to copy user input into a fixed-size stack buffer. Which register must be controlled to redirect the instruction pointer to your shellcode?
Select an answer to reveal the explanation
You have compromised a Linux jump host and need to access an internal web application on 192.168.1.50:80 that is firewalled from your local machine. You have SSH access to the jump host. Which command should you execute on your local machine to securely access the application via your browser?
Select an answer to reveal the explanation
An analyst is attempting to execute a custom C2 stager on a Windows 10 workstation with active Windows Defender. They decide to use a PowerShell one-liner that downloads a script from a remote server and executes it directly using the Invoke-Expression (IEX) cmdlet. Why is this method generally more effective than downloading an .exe file to the Desktop?
Select an answer to reveal the explanation
You have successfully obtained a NTLM hash dump from a domain controller. You intend to perform a pass-the-hash attack to move laterally. What is the most critical requirement for this technique to succeed in a modern Windows environment?
Select an answer to reveal the explanation
You have gained a low-privileged shell on a Windows system and discovered a service running as 'LocalSystem' with an unquoted executable path containing spaces. Which action is the most direct way to escalate privileges?
Select an answer to reveal the explanation
Answer all 11 questions to see your domain score breakdown
Sitting the PEN-200 under real exam conditions is a skill in itself. Candidates who underperform often do so not because of knowledge gaps, but because of poor time management or test anxiety. Use your final mock exam sessions to address both.
The PEN-200 exam lasts 90 minutes. Do not spend more than 90 seconds on any single question on the first pass. Flag difficult ones and return to them after completing the rest.
On every question, immediately eliminate obviously wrong choices. Even if you are unsure between two options, narrowing to two doubles your odds. Most PEN-200 distractors contain a subtle error — re-read the scenario constraint before committing to the answer that sounds most familiar.
OffSec writes many PEN-200 questions as realistic scenarios. Read the final sentence first — it tells you what is being asked. Then re-read the scenario with the question in mind to avoid wasting time on irrelevant details.
The real PEN-200 is a mental marathon lasting 90 minutes. In the week before your exam, complete at least two full timed mock sessions on separate days to build concentration stamina. If you cannot stay focused for 90 minutes in practice, you will struggle on exam day.
Questions
~285
On the real exam
Time limit
90 min
Official exam duration
Passing score
700/1000
Scaled scoring
The PEN-200 uses scaled scoring — your raw percentage correct is converted to a score out of 1000. Consistently scoring above 80% on mock exams puts you well above the 700/1000 threshold, giving you a buffer for any unexpected question types on the real exam.
Yes. Courseiva provides free PEN-200 mock exam questions across all official exam domains. The platform includes timed simulation, per-domain score breakdown, missed-question review, and readiness tracking. No account required — free forever, supported by advertising.
The practice test is optimised for learning: you see explanations after each question immediately. The mock exam is optimised for simulation: you answer all questions under time pressure and review at the end. Use practice tests for studying and mock exams for benchmarking.
Aim for consistent scores of 80% or above on full-length PEN-200 mock exams before booking your test date. The official passing score of 700/1000 corresponds to roughly 72–75% correct answers, so an 80% buffer accounts for difficulty variation and question styles on the real exam.
Most candidates who pass PEN-200 on their first attempt complete 3–5 full-length mock exams in the two weeks before their test. This is enough to identify final weak spots, build stamina, and verify readiness without over-stressing or running out of fresh questions.
No — all Courseiva questions are original, AI-assisted and checked against the public OffSec exam blueprints, with editorial oversight from an experienced network and security engineer. Exam dumps are memorised real exam questions shared illegally. Using dumps violates your OffSec certification agreement and can result in your certification being revoked. Our questions make you genuinely competent, not just test-day lucky.
Track your mock exam scores, see per-domain analytics, and benchmark readiness across every certification.
Sign Up FreeFree forever · Every certification included