OSCP+ Exam 2026/2027 | Offensive Security Certified
Professional | Complete Practice Questions, Answers &
Detailed Rationales
Section 1: Penetration Testing Fundamentals & Methodology
1. What is the primary purpose of reconnaissance during a
penetration test?
A. To immediately exploit the target
B. To gather information that can guide testing
C. To delete target logs
D. To install persistence
Answer: B.
Rationale: Reconnaissance identifies hosts, services, technologies,
users, and other information that helps determine where testing should
focus.
2. Which phase normally follows initial reconnaissance?
A. Reporting
B. Enumeration
C. Cleanup
D. Evidence destruction
Answer: B.
Rationale: Enumeration actively identifies available services, accounts,
shares, directories, and other target details.
3. What is the main difference between scanning and enumeration?
A. Scanning identifies potential services; enumeration extracts detailed
,information from them
B. Scanning always exploits services
C. Enumeration only applies to wireless networks
D. They are identical
Answer: A.
Rationale: Scanning generally identifies ports and services, while
enumeration attempts to obtain more detailed information from those
services.
4. Which principle should guide penetration-test activity?
A. Perform any action that works
B. Minimize unnecessary impact on systems
C. Avoid documenting findings
D. Modify evidence to prove exploitation
Answer: B.
Rationale: Professional testing should minimize disruption and remain
within the agreed rules of engagement.
5. What does a scope document primarily define?
A. Password complexity only
B. Systems and activities authorized for testing
C. The tester's salary
D. The final report format only
Answer: B.
Rationale: Scope establishes what systems, networks, applications, and
techniques are authorized.
6. What is a false positive?
A. A real vulnerability incorrectly classified as harmless
,B. An apparent vulnerability that is not actually present
C. A successful exploit
D. A confirmed credential
Answer: B.
Rationale: A false positive occurs when testing indicates a vulnerability
that further validation shows does not exist.
7. Why should penetration testers maintain detailed notes?
A. To replace authorization
B. To support reproducibility and reporting
C. To avoid validating findings
D. To hide mistakes
Answer: B.
Rationale: Accurate notes help reproduce findings, demonstrate
evidence, and produce a reliable report.
8. What is the purpose of a proof of concept (PoC)?
A. To demonstrate that a security issue is practically valid
B. To permanently compromise every host
C. To replace the report
D. To remove vulnerabilities automatically
Answer: A.
Rationale: A PoC demonstrates the security impact or exploitability of a
finding in a controlled manner.
9. What should a tester do when discovering an out-of-scope host?
A. Exploit it immediately
B. Ignore authorization requirements and continue
, C. Follow the engagement rules and obtain clarification if needed
D. Destroy the host's logs
Answer: C.
Rationale: Testing must remain within authorization and scope.
10. Which activity is most closely associated with enumeration?
A. Identifying SMB shares
B. Writing the executive summary
C. Encrypting the tester's disk
D. Archiving screenshots
Answer: A.
Rationale: Enumerating SMB shares provides detailed information
about resources exposed through SMB.
11. Why is manual validation important after automated scanning?
A. Automated scanners never produce useful results
B. It helps confirm findings and eliminate false positives
C. It makes authorization unnecessary
D. It guarantees exploitation
Answer: B.
Rationale: Manual testing confirms whether scanner findings are
genuine and determines their actual security impact.
12. What does attack surface refer to?
A. The total set of exposed points that could potentially be attacked
B. Only physical server locations
C. Only web applications
D. Only employee passwords
Professional | Complete Practice Questions, Answers &
Detailed Rationales
Section 1: Penetration Testing Fundamentals & Methodology
1. What is the primary purpose of reconnaissance during a
penetration test?
A. To immediately exploit the target
B. To gather information that can guide testing
C. To delete target logs
D. To install persistence
Answer: B.
Rationale: Reconnaissance identifies hosts, services, technologies,
users, and other information that helps determine where testing should
focus.
2. Which phase normally follows initial reconnaissance?
A. Reporting
B. Enumeration
C. Cleanup
D. Evidence destruction
Answer: B.
Rationale: Enumeration actively identifies available services, accounts,
shares, directories, and other target details.
3. What is the main difference between scanning and enumeration?
A. Scanning identifies potential services; enumeration extracts detailed
,information from them
B. Scanning always exploits services
C. Enumeration only applies to wireless networks
D. They are identical
Answer: A.
Rationale: Scanning generally identifies ports and services, while
enumeration attempts to obtain more detailed information from those
services.
4. Which principle should guide penetration-test activity?
A. Perform any action that works
B. Minimize unnecessary impact on systems
C. Avoid documenting findings
D. Modify evidence to prove exploitation
Answer: B.
Rationale: Professional testing should minimize disruption and remain
within the agreed rules of engagement.
5. What does a scope document primarily define?
A. Password complexity only
B. Systems and activities authorized for testing
C. The tester's salary
D. The final report format only
Answer: B.
Rationale: Scope establishes what systems, networks, applications, and
techniques are authorized.
6. What is a false positive?
A. A real vulnerability incorrectly classified as harmless
,B. An apparent vulnerability that is not actually present
C. A successful exploit
D. A confirmed credential
Answer: B.
Rationale: A false positive occurs when testing indicates a vulnerability
that further validation shows does not exist.
7. Why should penetration testers maintain detailed notes?
A. To replace authorization
B. To support reproducibility and reporting
C. To avoid validating findings
D. To hide mistakes
Answer: B.
Rationale: Accurate notes help reproduce findings, demonstrate
evidence, and produce a reliable report.
8. What is the purpose of a proof of concept (PoC)?
A. To demonstrate that a security issue is practically valid
B. To permanently compromise every host
C. To replace the report
D. To remove vulnerabilities automatically
Answer: A.
Rationale: A PoC demonstrates the security impact or exploitability of a
finding in a controlled manner.
9. What should a tester do when discovering an out-of-scope host?
A. Exploit it immediately
B. Ignore authorization requirements and continue
, C. Follow the engagement rules and obtain clarification if needed
D. Destroy the host's logs
Answer: C.
Rationale: Testing must remain within authorization and scope.
10. Which activity is most closely associated with enumeration?
A. Identifying SMB shares
B. Writing the executive summary
C. Encrypting the tester's disk
D. Archiving screenshots
Answer: A.
Rationale: Enumerating SMB shares provides detailed information
about resources exposed through SMB.
11. Why is manual validation important after automated scanning?
A. Automated scanners never produce useful results
B. It helps confirm findings and eliminate false positives
C. It makes authorization unnecessary
D. It guarantees exploitation
Answer: B.
Rationale: Manual testing confirms whether scanner findings are
genuine and determines their actual security impact.
12. What does attack surface refer to?
A. The total set of exposed points that could potentially be attacked
B. Only physical server locations
C. Only web applications
D. Only employee passwords