OSCP Practice Exam 2026/2027 | 300+ Penetration Testing
Questions, Correct Answers & Detailed Explanations
Section 1: Penetration Testing Fundamentals & Methodology
1. What is the primary purpose of defining scope before a penetration
test?
A. To maximize the number of vulnerabilities discovered
B. To establish which systems and activities are authorized
C. To guarantee administrative access
D. To eliminate the need for reporting
Answer: B
Explanation: Scope establishes the systems, networks, applications, and
testing activities that are authorized.
2. Which phase normally occurs before exploitation?
A. Reporting
B. Enumeration and vulnerability identification
C. Cleanup
D. Remediation
Answer: B
Explanation: Testers normally gather information and identify potential
attack paths before attempting exploitation.
3. What is the difference between reconnaissance and enumeration?
A. Reconnaissance gathers information broadly; enumeration extracts
,detailed service information
B. Enumeration is always passive
C. Reconnaissance only occurs after exploitation
D. They are identical
Answer: A
Explanation: Reconnaissance establishes an initial understanding of the
target, while enumeration digs deeper into exposed services and
resources.
4. What does the principle of least privilege recommend?
A. Give every user administrator rights
B. Give accounts only the permissions required for their tasks
C. Disable authentication
D. Use a single privileged account
Answer: B
Explanation: Least privilege limits unnecessary permissions and reduces
the impact of compromise.
5. Why should penetration testers maintain detailed notes?
A. Only for marketing
B. To reproduce findings and support reporting
C. To replace authorization documents
D. To avoid validating vulnerabilities
Answer: B
Explanation: Good notes allow findings, commands, evidence, and
attack paths to be reproduced and documented accurately.
,6. What is a false positive?
A. A real vulnerability that was missed
B. A reported issue that is not actually exploitable or present
C. A successful exploit
D. A system outage
Answer: B
Explanation: A false positive occurs when testing incorrectly identifies a
vulnerability.
7. What is a false negative?
A. A vulnerability incorrectly reported
B. A vulnerability that exists but is not detected
C. A successful login
D. A confirmed finding
Answer: B
Explanation: False negatives occur when testing fails to identify a
genuine weakness.
8. Why is vulnerability validation important?
A. It confirms whether a suspected weakness is genuine
B. It eliminates documentation
C. It guarantees root access
D. It prevents enumeration
, Answer: A
Explanation: Validation reduces false positives and provides stronger
evidence for a finding.
9. Which activity is generally considered passive reconnaissance?
A. Connecting directly to a target service
B. Reviewing publicly available information
C. Exploiting a web server
D. Running a port scan
Answer: B
Explanation: Passive reconnaissance gathers information without
directly interacting with the target infrastructure.
10. What should a tester do if an action appears outside the agreed
scope?
A. Continue because it may reveal a vulnerability
B. Stop and clarify authorization
C. Delete the target
D. Ignore the scope document
Answer: B
Explanation: Testing outside authorization can create legal, operational,
and contractual problems.
11. What is the purpose of a proof of concept (PoC)?
A. To demonstrate that a vulnerability can be reproduced
Questions, Correct Answers & Detailed Explanations
Section 1: Penetration Testing Fundamentals & Methodology
1. What is the primary purpose of defining scope before a penetration
test?
A. To maximize the number of vulnerabilities discovered
B. To establish which systems and activities are authorized
C. To guarantee administrative access
D. To eliminate the need for reporting
Answer: B
Explanation: Scope establishes the systems, networks, applications, and
testing activities that are authorized.
2. Which phase normally occurs before exploitation?
A. Reporting
B. Enumeration and vulnerability identification
C. Cleanup
D. Remediation
Answer: B
Explanation: Testers normally gather information and identify potential
attack paths before attempting exploitation.
3. What is the difference between reconnaissance and enumeration?
A. Reconnaissance gathers information broadly; enumeration extracts
,detailed service information
B. Enumeration is always passive
C. Reconnaissance only occurs after exploitation
D. They are identical
Answer: A
Explanation: Reconnaissance establishes an initial understanding of the
target, while enumeration digs deeper into exposed services and
resources.
4. What does the principle of least privilege recommend?
A. Give every user administrator rights
B. Give accounts only the permissions required for their tasks
C. Disable authentication
D. Use a single privileged account
Answer: B
Explanation: Least privilege limits unnecessary permissions and reduces
the impact of compromise.
5. Why should penetration testers maintain detailed notes?
A. Only for marketing
B. To reproduce findings and support reporting
C. To replace authorization documents
D. To avoid validating vulnerabilities
Answer: B
Explanation: Good notes allow findings, commands, evidence, and
attack paths to be reproduced and documented accurately.
,6. What is a false positive?
A. A real vulnerability that was missed
B. A reported issue that is not actually exploitable or present
C. A successful exploit
D. A system outage
Answer: B
Explanation: A false positive occurs when testing incorrectly identifies a
vulnerability.
7. What is a false negative?
A. A vulnerability incorrectly reported
B. A vulnerability that exists but is not detected
C. A successful login
D. A confirmed finding
Answer: B
Explanation: False negatives occur when testing fails to identify a
genuine weakness.
8. Why is vulnerability validation important?
A. It confirms whether a suspected weakness is genuine
B. It eliminates documentation
C. It guarantees root access
D. It prevents enumeration
, Answer: A
Explanation: Validation reduces false positives and provides stronger
evidence for a finding.
9. Which activity is generally considered passive reconnaissance?
A. Connecting directly to a target service
B. Reviewing publicly available information
C. Exploiting a web server
D. Running a port scan
Answer: B
Explanation: Passive reconnaissance gathers information without
directly interacting with the target infrastructure.
10. What should a tester do if an action appears outside the agreed
scope?
A. Continue because it may reveal a vulnerability
B. Stop and clarify authorization
C. Delete the target
D. Ignore the scope document
Answer: B
Explanation: Testing outside authorization can create legal, operational,
and contractual problems.
11. What is the purpose of a proof of concept (PoC)?
A. To demonstrate that a vulnerability can be reproduced