Sample questions
OffSec PEN-200 / OSCP Concepts practice questions
You are performing a network scan on a client segment and notice that a host responds to ICMP echo requests but shows all TCP ports as 'filtered' when using Nmap. Which conclusion…
You are auditing a web application and notice it uses base64 encoding to store user credentials in a cookie. What is the most accurate assessment of this security practice?
During an authorized penetration test, you want to perform a client-side attack by delivering a malicious HTA file via a phishing email. Which technique is most effective to execut…
Which of the following describes a successful Path Traversal attack in a web application?
Refer to the exhibit. [!] Error compiling payload: Function 'VirtualAlloc' not found in target assembly scope. An operator is writing a custom process injection loader in C# and…
You have identified a vulnerable service using an outdated version of a CMS. You successfully locate a public exploit script on GitHub. What is the most critical first step before…
During external reconnaissance you collect DNS records for a target organization and find an MX record pointing to mail.example.com. You want to identify the IP addresses of other…
During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a Windows host. You want to crack it offline to recover the plaintext password. Which tool…
When exploiting a service via 'Modify' permissions on its binary, why is it necessary to restart the service?
During an internal assessment you run a TCP SYN scan and note that a host responds with an RST/ACK for every probed port. What does this behavior most reliably indicate about the t…
During an internal Active Directory assessment, you have compromised a standard domain user account. You run BloodHound and identify that this user has the 'GenericAll' permission…
Which of the following is the most effective way to prevent Cross-Site Scripting (XSS) in a web application?
What is the most likely security risk associated with the configuration shown in the exhibit?
When performing a DCSync attack, what is the core mechanism being exploited?
What is the primary purpose of an exploit payload in a buffer overflow context?
When evaluating a web application for Cross-Site Scripting vulnerabilities during a penetration test, which TWO input contexts should you examine because they frequently lead to ex…
During enumeration, you discover that the registry keys 'HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' and 'HKCU\SOFTWARE\Policies\Microsoft\Windows\Ins…
You are adapting a public exploit whose payload is a reverse shell. The exploit runs and the service reports success, but your netcat listener never receives a connection. Which ca…
Refer to the exhibit. ```http HTTP/1.1 200 OK Server: nginx Content-Type: text/html; charset=UTF-8 Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'…
During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?
During an assessment, you identify a Cross-Site Scripting vulnerability that allows you to execute arbitrary JavaScript in the context of a victim user's browser session. What is t…
During an external penetration test, you discover a web application that uses a JSON Web Token (JWT) for authentication. The token header is {"alg":"HS256","typ":"JWT"}, and you ha…
Which of the following describes the 'Open Redirect' vulnerability often used in phishing attacks?
A penetration tester is investigating scheduled tasks for potential privilege escalation. Which TWO conditions must be met for a scheduled task to be successfully exploited for gai…