OSCP Exam 2026/2027 | Offensive Security Certified
Professional | 300+ Practice Questions, Correct Answers &
Detailed Rationales
Section 1: Penetration Testing Fundamentals
1. What is the primary purpose of reconnaissance?
A. To delete evidence
B. To gather information about the target
C. To install persistence
D. To encrypt files
Answer: B
Rationale: Reconnaissance identifies information that can guide later
enumeration and testing.
2. Which phase normally follows reconnaissance?
A. Reporting
B. Enumeration
C. Cleanup
D. Remediation
Answer: B
Rationale: Enumeration actively identifies services, hosts, users, and
other target information.
3. What does the principle of least privilege require?
A. Users receive administrator access
B. Systems use no authentication
C. Accounts receive only necessary permissions
D. Every service runs as root
,Answer: C
Rationale: Least privilege minimizes permissions to those required for
legitimate tasks.
4. What is the main objective of vulnerability assessment?
A. Identify weaknesses
B. Destroy systems
C. Modify production data
D. Disable monitoring
Answer: A
Rationale: Vulnerability assessment focuses on discovering weaknesses
that could be exploited.
5. What is exploitation?
A. Documenting findings
B. Using a vulnerability to obtain an intended security result
C. Backing up files
D. Scanning only DNS
Answer: B
Rationale: Exploitation demonstrates the practical security impact of a
vulnerability.
6. What is a proof of concept (PoC)?
A. Evidence demonstrating that a vulnerability works
B. A firewall rule
C. A password policy
D. A network diagram only
Answer: A
Rationale: A PoC provides controlled evidence that a security weakness
can be demonstrated.
,7. What is the purpose of a penetration-testing scope?
A. Define authorized boundaries
B. Guarantee administrator access
C. Remove legal requirements
D. Disable all security controls
Answer: A
Rationale: Scope defines what systems, techniques, and activities are
authorized.
8. Which activity is most likely passive reconnaissance?
A. Port scanning
B. Service exploitation
C. Reviewing public DNS records
D. Password spraying
Answer: C
Rationale: Reviewing publicly available information can be performed
without directly interacting with the target service.
9. What does attack surface refer to?
A. The number of employees
B. The collection of exposed points that could be attacked
C. Disk capacity
D. CPU utilization
Answer: B
Rationale: The attack surface includes reachable services, applications,
interfaces, and other exposure points.
10. Why is enumeration important?
A. It replaces exploitation
B. It provides detailed information about discovered services
, C. It automatically patches systems
D. It removes vulnerabilities
Answer: B
Rationale: Enumeration turns basic discovery into detailed information
useful for assessing attack paths.
11. What is a false positive?
A. A real vulnerability
B. A benign condition incorrectly reported as a vulnerability
C. A successful exploit
D. A confirmed compromise
Answer: B
Rationale: A false positive occurs when a scanner or analyst incorrectly
identifies something as a security issue.
12. What is a false negative?
A. A vulnerability that is missed
B. A vulnerability that is confirmed
C. A successful login
D. A documented finding
Answer: A
Rationale: A false negative occurs when an actual weakness is not
detected.
13. Why should penetration testers maintain notes?
A. To increase CPU performance
B. To support reproducibility and reporting
C. To disable logging
D. To hide vulnerabilities
Answer: B
Professional | 300+ Practice Questions, Correct Answers &
Detailed Rationales
Section 1: Penetration Testing Fundamentals
1. What is the primary purpose of reconnaissance?
A. To delete evidence
B. To gather information about the target
C. To install persistence
D. To encrypt files
Answer: B
Rationale: Reconnaissance identifies information that can guide later
enumeration and testing.
2. Which phase normally follows reconnaissance?
A. Reporting
B. Enumeration
C. Cleanup
D. Remediation
Answer: B
Rationale: Enumeration actively identifies services, hosts, users, and
other target information.
3. What does the principle of least privilege require?
A. Users receive administrator access
B. Systems use no authentication
C. Accounts receive only necessary permissions
D. Every service runs as root
,Answer: C
Rationale: Least privilege minimizes permissions to those required for
legitimate tasks.
4. What is the main objective of vulnerability assessment?
A. Identify weaknesses
B. Destroy systems
C. Modify production data
D. Disable monitoring
Answer: A
Rationale: Vulnerability assessment focuses on discovering weaknesses
that could be exploited.
5. What is exploitation?
A. Documenting findings
B. Using a vulnerability to obtain an intended security result
C. Backing up files
D. Scanning only DNS
Answer: B
Rationale: Exploitation demonstrates the practical security impact of a
vulnerability.
6. What is a proof of concept (PoC)?
A. Evidence demonstrating that a vulnerability works
B. A firewall rule
C. A password policy
D. A network diagram only
Answer: A
Rationale: A PoC provides controlled evidence that a security weakness
can be demonstrated.
,7. What is the purpose of a penetration-testing scope?
A. Define authorized boundaries
B. Guarantee administrator access
C. Remove legal requirements
D. Disable all security controls
Answer: A
Rationale: Scope defines what systems, techniques, and activities are
authorized.
8. Which activity is most likely passive reconnaissance?
A. Port scanning
B. Service exploitation
C. Reviewing public DNS records
D. Password spraying
Answer: C
Rationale: Reviewing publicly available information can be performed
without directly interacting with the target service.
9. What does attack surface refer to?
A. The number of employees
B. The collection of exposed points that could be attacked
C. Disk capacity
D. CPU utilization
Answer: B
Rationale: The attack surface includes reachable services, applications,
interfaces, and other exposure points.
10. Why is enumeration important?
A. It replaces exploitation
B. It provides detailed information about discovered services
, C. It automatically patches systems
D. It removes vulnerabilities
Answer: B
Rationale: Enumeration turns basic discovery into detailed information
useful for assessing attack paths.
11. What is a false positive?
A. A real vulnerability
B. A benign condition incorrectly reported as a vulnerability
C. A successful exploit
D. A confirmed compromise
Answer: B
Rationale: A false positive occurs when a scanner or analyst incorrectly
identifies something as a security issue.
12. What is a false negative?
A. A vulnerability that is missed
B. A vulnerability that is confirmed
C. A successful login
D. A documented finding
Answer: A
Rationale: A false negative occurs when an actual weakness is not
detected.
13. Why should penetration testers maintain notes?
A. To increase CPU performance
B. To support reproducibility and reporting
C. To disable logging
D. To hide vulnerabilities
Answer: B