OffSec · 2026 Edition
A complete preparation guide, edited by Johnson Ajibi, a network and security engineer with 12+ years' experience. Covers the exam format,all 11 blueprint domains, a week-by-week study plan, and proven tips for passing first time.
2–4 months
Prep time
Intermediate
Difficulty
60–90
Exam questions
700/1000
Pass mark
Exam code
PEN-200
Full name
OffSec PEN-200 / OSCP Concepts
Vendor
OffSec
Duration
90 minutes
Questions
~0 items
Passing score
700/1000 (scaled)
Domains covered
11 blueprint domains
Recommended experience
Foundational IT knowledge recommended
Typical prep time
2–4 months
Domain percentage weights are not currently available for this exam. The checklist below is still useful for planning your study.
Phase 1
Client-Side Attacks
Tip: Start with the official Client-Side Attacks objectives, then practise questions on it.
Phase 2
Enumeration and Reconnaissance
Tip: Cover the Enumeration and Reconnaissance objectives, then answer practice questions to confirm you can apply them.
Phase 3
Active Directory Attacks
Tip: Cover the Active Directory Attacks objectives, then answer practice questions to confirm you can apply them.
Phase 4
Public Exploits
Tip: Cover the Public Exploits objectives, then answer practice questions to confirm you can apply them.
Phase 5
Web Application Attacks
Tip: Cover the Web Application Attacks objectives, then answer practice questions to confirm you can apply them.
Phase 6
Linux Privilege Escalation
Tip: Cover the Linux Privilege Escalation objectives, then answer practice questions to confirm you can apply them.
Phase 7
Buffer Overflow Fundamentals
Tip: Cover the Buffer Overflow Fundamentals objectives, then answer practice questions to confirm you can apply them.
Phase 8
Port Redirection and Tunneling
Tip: Cover the Port Redirection and Tunneling objectives, then answer practice questions to confirm you can apply them.
Phase 9
Antivirus Evasion
Tip: Cover the Antivirus Evasion objectives, then answer practice questions to confirm you can apply them.
Phase 10
Password Attacks
Tip: Cover the Password Attacks objectives, then answer practice questions to confirm you can apply them.
Phase 11
Windows Privilege Escalation
Tip: Finish with Windows Privilege Escalation, then re-test your weakest earlier domain before a mock exam.
Study the official exam blueprint — weight percentages tell you exactly where to invest prep time.
Practise scenario-based questions regularly — every modern cert exam is scenario-heavy.
Use spaced repetition to retain what you've learned (Courseiva does this automatically).
Book your exam date once you're scoring 80%+ consistently on practice tests.
Review explanations for every wrong answer, not just the question — the 'why' is what makes it stick.
Apply everything in this guide with adaptive practice questions, detailed answer explanations, and domain analytics.