OSCP+ Certification Exam 2026/2027 | Complete Penetration
Testing Practice Questions, Answers & Detailed Rationales
Section 1: Penetration Testing Fundamentals — Questions 1–30
1. What is the primary objective of a penetration test?
A. Permanently compromise the target
B. Identify and validate security weaknesses in an authorized
environment
C. Install persistent malware
D. Disable security monitoring
Answer: B
Rationale: A penetration test evaluates whether vulnerabilities can be
exploited within an agreed scope and documents their security impact.
2. What should a penetration tester establish before testing begins?
A. Persistence mechanisms
B. Rules of engagement and scope
C. Backup passwords
D. Malware infrastructure
Answer: B
Rationale: Scope and rules of engagement define authorized targets,
techniques, timing, and limitations.
3. Which activity generally occurs first during a penetration test?
A. Privilege escalation
B. Post-exploitation
,C. Reconnaissance
D. Data destruction
Answer: C
Rationale: Reconnaissance gathers information that helps identify
potential attack surfaces.
4. What does enumeration attempt to discover?
A. Only physical addresses
B. Detailed information about exposed services and resources
C. Employee salaries
D. Backup locations exclusively
Answer: B
Rationale: Enumeration extracts detailed information from discovered
services such as users, shares, directories, and software versions.
5. What is a false positive?
A. A real vulnerability incorrectly reported as safe
B. A non-vulnerable condition incorrectly identified as vulnerable
C. A successful exploit
D. A failed scan
Answer: B
Rationale: A false positive occurs when testing incorrectly identifies a
security issue that is not actually exploitable or present.
6. Why is manual validation important?
A. It eliminates documentation
B. It confirms whether automated findings are genuine
,C. It guarantees exploitation
D. It disables firewalls
Answer: B
Rationale: Automated scanners can misidentify conditions, so manual
verification improves accuracy.
7. What does attack surface mean?
A. The physical size of a server
B. The collection of accessible points through which a system can
potentially be attacked
C. The number of users logged in
D. The CPU utilization
Answer: B
Rationale: The attack surface includes exposed services, applications,
interfaces, accounts, and other accessible components.
8. Which principle limits testing to authorized systems?
A. Least privilege
B. Scope control
C. Defense in depth
D. Obfuscation
Answer: B
Rationale: Scope control ensures testing activities remain within the
systems and techniques authorized by the engagement.
9. What is vulnerability validation?
A. Removing every detected service
B. Confirming that a suspected weakness is real and meaningful
, C. Encrypting the target
D. Reinstalling the operating system
Answer: B
Rationale: Validation determines whether a finding is legitimate and
whether exploitation is possible under the test conditions.
10. Why should testers maintain detailed notes?
A. To avoid reporting findings
B. To reproduce results and support the final report
C. To hide vulnerabilities
D. To increase scan speed
Answer: B
Rationale: Detailed notes provide evidence, help reproduce findings,
and support accurate reporting.
11. What is a proof of concept?
A. Evidence demonstrating that a vulnerability can be triggered or
exploited
B. A backup image
C. A network diagram only
D. A password policy
Answer: A
Rationale: A proof of concept demonstrates the practical effect of a
vulnerability without unnecessary impact.
12. Which action best demonstrates responsible penetration testing?
A. Deleting production data
B. Testing within agreed limits
Testing Practice Questions, Answers & Detailed Rationales
Section 1: Penetration Testing Fundamentals — Questions 1–30
1. What is the primary objective of a penetration test?
A. Permanently compromise the target
B. Identify and validate security weaknesses in an authorized
environment
C. Install persistent malware
D. Disable security monitoring
Answer: B
Rationale: A penetration test evaluates whether vulnerabilities can be
exploited within an agreed scope and documents their security impact.
2. What should a penetration tester establish before testing begins?
A. Persistence mechanisms
B. Rules of engagement and scope
C. Backup passwords
D. Malware infrastructure
Answer: B
Rationale: Scope and rules of engagement define authorized targets,
techniques, timing, and limitations.
3. Which activity generally occurs first during a penetration test?
A. Privilege escalation
B. Post-exploitation
,C. Reconnaissance
D. Data destruction
Answer: C
Rationale: Reconnaissance gathers information that helps identify
potential attack surfaces.
4. What does enumeration attempt to discover?
A. Only physical addresses
B. Detailed information about exposed services and resources
C. Employee salaries
D. Backup locations exclusively
Answer: B
Rationale: Enumeration extracts detailed information from discovered
services such as users, shares, directories, and software versions.
5. What is a false positive?
A. A real vulnerability incorrectly reported as safe
B. A non-vulnerable condition incorrectly identified as vulnerable
C. A successful exploit
D. A failed scan
Answer: B
Rationale: A false positive occurs when testing incorrectly identifies a
security issue that is not actually exploitable or present.
6. Why is manual validation important?
A. It eliminates documentation
B. It confirms whether automated findings are genuine
,C. It guarantees exploitation
D. It disables firewalls
Answer: B
Rationale: Automated scanners can misidentify conditions, so manual
verification improves accuracy.
7. What does attack surface mean?
A. The physical size of a server
B. The collection of accessible points through which a system can
potentially be attacked
C. The number of users logged in
D. The CPU utilization
Answer: B
Rationale: The attack surface includes exposed services, applications,
interfaces, accounts, and other accessible components.
8. Which principle limits testing to authorized systems?
A. Least privilege
B. Scope control
C. Defense in depth
D. Obfuscation
Answer: B
Rationale: Scope control ensures testing activities remain within the
systems and techniques authorized by the engagement.
9. What is vulnerability validation?
A. Removing every detected service
B. Confirming that a suspected weakness is real and meaningful
, C. Encrypting the target
D. Reinstalling the operating system
Answer: B
Rationale: Validation determines whether a finding is legitimate and
whether exploitation is possible under the test conditions.
10. Why should testers maintain detailed notes?
A. To avoid reporting findings
B. To reproduce results and support the final report
C. To hide vulnerabilities
D. To increase scan speed
Answer: B
Rationale: Detailed notes provide evidence, help reproduce findings,
and support accurate reporting.
11. What is a proof of concept?
A. Evidence demonstrating that a vulnerability can be triggered or
exploited
B. A backup image
C. A network diagram only
D. A password policy
Answer: A
Rationale: A proof of concept demonstrates the practical effect of a
vulnerability without unnecessary impact.
12. Which action best demonstrates responsible penetration testing?
A. Deleting production data
B. Testing within agreed limits