OSCP & OSCP+ (PEN-200) Practice Questions and Lab Tasks (2026)

Prepare for the OSCP and OSCP+ (PEN-200) certification exam with real exam questions and answers. Access classroom training, mock tests, and official study materials with WebAsha Technologies. Pass on your first attempt!

Jan 24, 2025 - 17:33
Updated: 3 days ago
119k
OSCP & OSCP+ (PEN-200) Practice Questions and Lab Tasks (2026)

Quick answer: OSCP and OSCP+ are hands-on penetration testing exams from OffSec based on the PEN-200 course. You pass by compromising machines in a lab network and writing a professional report, not by memorising questions. The best preparation is to rebuild the skills yourself: enumeration, web and service exploitation, privilege escalation, Active Directory, pivoting and clear reporting. This page gives original practice tasks and a study plan mapped to public exam skills.

Key takeaways

  • OffSec does not publish its exam machines, so ignore anyone selling real OSCP questions and practise from the public PEN-200 syllabus instead.
  • Train for enumeration discipline, since stalled boxes usually come from missed services rather than missing exploits, and keep notes you can reuse.
  • Rehearse the exam format: a long timed practical on isolated machines, followed by a report, using lab systems you own or are authorised to test.

OffSec does not publish its real exam machines, and sharing actual exam content breaches the exam agreement you accept when you book an OffSec exam. Any site offering "real OSCP questions" or "dumps" is both unreliable and a policy risk. Everything below is written from OffSec's public PEN-200 syllabus so you practise the right skills ethically, on systems you own or are explicitly authorised to test.

What the OSCP and OSCP+ exam actually looks like

It is a practical exam. You get remote access to a lab network and must demonstrate control of the target machines, then submit a report. OffSec moved the modern exam to a structure that combines standalone machines with an Active Directory set.

ItemDetail (confirm on OffSec's page before booking)
CoursePEN-200 (Penetration Testing with Kali Linux)
CredentialOSCP, or OSCP+ which adds a time-limited validity and continuing-education element
FormatHands-on exploitation of lab machines, roughly 24 hours, followed by a report deadline
Score to pass70 points out of 100
Active Directory setAn assumed-breach AD chain worth up to 40 points; pivoting may be required
Standalone machinesRemaining points come from standalone targets via their local and proof flags
MetasploitAllowed on one target only, and not for pivoting

The exact machine count, timings and point split are set by OffSec and change over time, so treat the numbers above as orientation and read the official OSCP exam FAQ before your sitting. The one thing that never changes: a machine that is not reported with working evidence scores nothing.

Which skills the exam tests

PEN-200's public syllabus maps to a handful of skill areas. Build a personal lab and drill each one until it is routine:

  • Enumeration of ports, services and web content, including UDP, so you never miss an entry point.
  • Web application testing for common flaws such as injection, file upload and authentication weaknesses.
  • Service exploitation using public, well-documented vulnerabilities and how to adapt existing proof-of-concept code.
  • Privilege escalation on Linux and Windows, by reading the system rather than running every script blindly.
  • Active Directory attack paths: credential reuse, Kerberos abuse and lateral movement inside a test domain.
  • Pivoting and tunnelling to reach segmented networks.
  • Reporting: clear, reproducible steps a defender could follow to verify and fix each finding.

Practice tasks, by skill area (lab only)

Set up a lab you own, for example a few intentionally vulnerable virtual machines and a small Windows domain, or a legal training platform. Then work the tasks below. They are objectives, not an attack recipe, so you learn to find the method yourself, which is exactly what the exam rewards.

Enumeration

  1. Scan a host you control and produce a written inventory of every open TCP and UDP service and its version. Note which services are worth investigating first and why.
  2. For a web service, map the directory structure and list the technologies in use. Record what each finding might lead to.
  3. Write a short checklist you can reuse so your enumeration is consistent under time pressure.

Common mistake: rushing enumeration. Most stuck candidates have simply not looked hard enough at what they already found.

Web and service exploitation

  1. Stand up a deliberately vulnerable web app (many are published for training) and identify an injection or upload flaw. Explain the root cause and the fix, not just the exploit.
  2. Take a public proof-of-concept for a known CVE, read it line by line, and describe what each part does before you run it in your lab.
  3. Document how a defender would detect the same activity in logs. This habit sharpens both your attack notes and your report.

Privilege escalation

  1. On a Linux VM, enumerate users, groups, scheduled jobs, writable paths and special permissions. From that evidence, work out a realistic escalation route.
  2. Repeat on a Windows VM: services, scheduled tasks, privileges and misconfigurations. Tools such as enumeration scripts help, but practise reading the output yourself.
  3. For each route you find, write the one configuration change that would have closed it.

Active Directory and pivoting

  1. Build a small test domain. Practise credential discovery and reuse, then move from one host to another using only accounts you have legitimately recovered in your lab.
  2. Set up two network segments and practise reaching the second one through a foothold on the first, using standard tunnelling.
  3. Note the detection signal each step would create for a blue team, which is useful whether you go on to red or blue work.

Reporting

  1. Write a full report for one lab machine: scope, steps to reproduce, evidence, impact and remediation. Use OffSec's report template as your structure.
  2. Have a peer try to reproduce your steps from the report alone. If they cannot, your report is not finished.

A realistic study plan

Treat preparation as skill-building, not question-hunting:

  • Work through the PEN-200 material and its lab machines end to end.
  • Supplement with legal practice platforms and intentionally vulnerable machines you download and run yourself.
  • Simulate exam conditions: a fixed time box, your own notes, and a report written the same day.
  • Keep a personal methodology document and a privilege-escalation checklist for Linux and Windows.
  • Rehearse time management so you move on from a stuck target and come back later.

If you want a structured path with lab access and mentoring, the OSCP (PEN-200) training with Kali Linux at WebAsha is built around this kind of hands-on practice. For the certification context and how OSCP compares to other penetration testing tracks, see our guide on CPENT and OSCP and the walkthrough on how to pass the OSCP exam on your first attempt.

Only test systems you own or have written authorisation to assess. In India, unauthorised access to a computer system is an offence under the Information Technology Act, 2000. The skills on this page are for lab practice and authorised engagements, and a professional report always ends with how to fix what you found. If you are new to the field, start with the fundamentals in our penetration tester skills and certifications guide before attempting OSCP.

Related reading

Frequently Asked Questions

OSCP is OffSec's hands-on penetration testing certification, earned through the PEN-200 course. It proves you can enumerate, exploit and escalate privileges on lab machines and write a professional report, rather than answer written questions.

OSCP+ is the updated version of the credential. It covers the same practical skills but adds a time-limited validity and a continuing-education element, so holders show their skills stay current. Confirm the current terms on OffSec's official pages.

No legitimate ones. OffSec does not publish its exam machines, and sharing real exam content breaches the exam agreement. Sites selling OSCP dumps are unreliable and risky. Prepare from the public PEN-200 syllabus and hands-on lab practice instead.

You need 70 points out of 100. Points come from an Active Directory set worth up to 40 points and from standalone machines via their local and proof flags. A target only scores if your report reproduces the result.

Only in a limited way. OffSec allows Metasploit on a single target machine and does not allow it for pivoting. Most of the exam must be completed with manual techniques, so practise without leaning on automated exploitation.

It depends on your starting point. People new to penetration testing often spend four to six months of steady practice, while those with strong Linux, networking and scripting backgrounds may need two to three months of focused lab work.

Yes. The modern exam includes an assumed-breach Active Directory set worth a large share of the points, often requiring lateral movement and pivoting. Build a small test domain and practise credential reuse and movement between hosts you control.

Yes, as long as you only test systems you own or are authorised to assess. Use your own virtual machines, intentionally vulnerable images or legal training platforms. In India, unauthorised access to other systems is an offence under the IT Act, 2000.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Aayushi Sinha

With a passion for staying on the cutting edge of technology trends, I am dedicated to delivering content that not only informs but also inspires. Whether you need in-depth analysis pieces, informative guides, or thought-provoking opinion pieces, I craft content that resonates with tech enthusiasts and professionals alike.