Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 97 pages
Exam (elaborations)

OSCP+ Study Guide 2026/2027 | Complete Practice Questions & Detailed Rationales | Offensive Security

Document preview thumbnail
Preview 4 out of 97 pages

OSCP+ Study Guide 2026/2027 | Complete Practice Questions & Detailed Rationales | Offensive Security

Content preview

OSCP+ Study Guide 2026/2027 | Complete Practice Questions
& Detailed Rationales | Offensive Security


Section 1: Penetration Testing Methodology & Scoping
1. What is the primary purpose of defining scope before a penetration
test?
A. To maximize the number of vulnerabilities discovered
B. To establish what systems and activities are authorized
C. To eliminate the need for documentation
D. To guarantee administrative access
Answer: B
Rationale: Scope establishes the systems, networks, applications, and
testing activities that are authorized.
2. Which activity should normally occur before exploitation?
A. Data destruction
B. Enumeration
C. Persistence
D. Cleanup
Answer: B
Rationale: Enumeration identifies services, technologies, users, and
attack surfaces before exploitation is attempted.
3. What is the main advantage of maintaining detailed penetration-
testing notes?
A. They replace technical testing
B. They support reproducibility and reporting

,C. They eliminate vulnerabilities
D. They prevent all false positives
Answer: B
Rationale: Good notes allow findings and successful techniques to be
reproduced and accurately documented.
4. Which finding generally deserves the highest priority?
A. Publicly exposed administrative access with weak authentication
B. Missing cosmetic webpage content
C. An unused image file
D. A low-impact information disclosure
Answer: A
Rationale: Exposed administrative access combined with weak
authentication can provide direct compromise.
5. What does the principle of least privilege require?
A. Users receive every available permission
B. Users receive only permissions necessary for their tasks
C. Administrators cannot access servers
D. Services must run as root
Answer: B
Rationale: Least privilege limits permissions to those required for
legitimate operations.
6. Why should testers validate a suspected vulnerability manually?
A. To increase scan duration
B. To confirm exploitability and reduce false positives
C. To avoid documenting the finding
D. To disable security controls

,Answer: B
Rationale: Manual validation determines whether an automated finding
is actually exploitable.
7. What is a common goal of initial reconnaissance?
A. Identify the target's attack surface
B. Delete system logs
C. Change passwords
D. Install persistence
Answer: A
Rationale: Reconnaissance establishes information about hosts,
domains, services, and technologies.
8. What should a tester do if an action appears outside the authorized
scope?
A. Continue because it may reveal a vulnerability
B. Stop and verify authorization
C. Attempt it anonymously
D. Hide the activity
Answer: B
Rationale: Testing outside scope can become unauthorized activity and
must be avoided.
9. What is the purpose of a proof of concept during a penetration
test?
A. Demonstrate that a vulnerability is practically exploitable
B. Replace the final report
C. Destroy compromised systems
D. Guarantee persistence

, Answer: A
Rationale: A proof of concept demonstrates the security impact
without unnecessary actions.
10. Which principle helps prevent unnecessary damage during
exploitation?
A. Maximum privilege
B. Minimum necessary impact
C. Unlimited persistence
D. Maximum data collection
Answer: B
Rationale: Professional testing should demonstrate impact while
minimizing disruption and unnecessary access.
11. What is attack-surface reduction?
A. Increasing the number of exposed services
B. Removing or restricting unnecessary exposure
C. Adding more administrative accounts
D. Disabling all monitoring
Answer: B
Rationale: Reducing exposed services, interfaces, and privileges
decreases opportunities for attack.
12. Why is evidence collection important?
A. It supports verification of findings
B. It guarantees remediation
C. It eliminates vulnerabilities
D. It replaces enumeration

Document information

Uploaded on
September 13, 2026
Number of pages
97
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.6
(24)
Sold
112
Followers
3
Items
8630
Last sold
21 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions