Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 102 pages
Exam (elaborations)

OSCP+ Certification Exam 2026/2027 | Complete Penetration Testing Practice Questions, Answers & Detailed Rationales

Document preview thumbnail
Preview 4 out of 102 pages

OSCP+ Certification Exam 2026/2027 | Complete Penetration Testing Practice Questions, Answers & Detailed Rationales

Content preview

OSCP+ Certification Exam 2026/2027 | Complete Penetration
Testing Practice Questions, Answers & Detailed Rationales


Section 1: Penetration Testing Fundamentals — Questions 1–30
1. What is the primary objective of a penetration test?
A. Permanently compromise the target
B. Identify and validate security weaknesses in an authorized
environment
C. Install persistent malware
D. Disable security monitoring
Answer: B
Rationale: A penetration test evaluates whether vulnerabilities can be
exploited within an agreed scope and documents their security impact.
2. What should a penetration tester establish before testing begins?
A. Persistence mechanisms
B. Rules of engagement and scope
C. Backup passwords
D. Malware infrastructure
Answer: B
Rationale: Scope and rules of engagement define authorized targets,
techniques, timing, and limitations.
3. Which activity generally occurs first during a penetration test?
A. Privilege escalation
B. Post-exploitation

,C. Reconnaissance
D. Data destruction
Answer: C
Rationale: Reconnaissance gathers information that helps identify
potential attack surfaces.
4. What does enumeration attempt to discover?
A. Only physical addresses
B. Detailed information about exposed services and resources
C. Employee salaries
D. Backup locations exclusively
Answer: B
Rationale: Enumeration extracts detailed information from discovered
services such as users, shares, directories, and software versions.
5. What is a false positive?
A. A real vulnerability incorrectly reported as safe
B. A non-vulnerable condition incorrectly identified as vulnerable
C. A successful exploit
D. A failed scan
Answer: B
Rationale: A false positive occurs when testing incorrectly identifies a
security issue that is not actually exploitable or present.
6. Why is manual validation important?
A. It eliminates documentation
B. It confirms whether automated findings are genuine

,C. It guarantees exploitation
D. It disables firewalls
Answer: B
Rationale: Automated scanners can misidentify conditions, so manual
verification improves accuracy.
7. What does attack surface mean?
A. The physical size of a server
B. The collection of accessible points through which a system can
potentially be attacked
C. The number of users logged in
D. The CPU utilization
Answer: B
Rationale: The attack surface includes exposed services, applications,
interfaces, accounts, and other accessible components.
8. Which principle limits testing to authorized systems?
A. Least privilege
B. Scope control
C. Defense in depth
D. Obfuscation
Answer: B
Rationale: Scope control ensures testing activities remain within the
systems and techniques authorized by the engagement.
9. What is vulnerability validation?
A. Removing every detected service
B. Confirming that a suspected weakness is real and meaningful

, C. Encrypting the target
D. Reinstalling the operating system
Answer: B
Rationale: Validation determines whether a finding is legitimate and
whether exploitation is possible under the test conditions.
10. Why should testers maintain detailed notes?
A. To avoid reporting findings
B. To reproduce results and support the final report
C. To hide vulnerabilities
D. To increase scan speed
Answer: B
Rationale: Detailed notes provide evidence, help reproduce findings,
and support accurate reporting.
11. What is a proof of concept?
A. Evidence demonstrating that a vulnerability can be triggered or
exploited
B. A backup image
C. A network diagram only
D. A password policy
Answer: A
Rationale: A proof of concept demonstrates the practical effect of a
vulnerability without unnecessary impact.
12. Which action best demonstrates responsible penetration testing?
A. Deleting production data
B. Testing within agreed limits

Document information

Uploaded on
September 13, 2026
Number of pages
102
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.6
(24)
Sold
112
Followers
3
Items
8630
Last sold
21 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions