OSCP & OSCP+ (PEN-200) Practice Questions and Lab Tasks (2026)
Prepare for the OSCP and OSCP+ (PEN-200) certification exam with real exam questions and answers. Access classroom training, mock tests, and official study materials with WebAsha Technologies. Pass on your first attempt!
Quick answer: OSCP and OSCP+ are hands-on penetration testing exams from OffSec based on the PEN-200 course. You pass by compromising machines in a lab network and writing a professional report, not by memorising questions. The best preparation is to rebuild the skills yourself: enumeration, web and service exploitation, privilege escalation, Active Directory, pivoting and clear reporting. This page gives original practice tasks and a study plan mapped to public exam skills.
Key takeaways
- OffSec does not publish its exam machines, so ignore anyone selling real OSCP questions and practise from the public PEN-200 syllabus instead.
- Train for enumeration discipline, since stalled boxes usually come from missed services rather than missing exploits, and keep notes you can reuse.
- Rehearse the exam format: a long timed practical on isolated machines, followed by a report, using lab systems you own or are authorised to test.
OffSec does not publish its real exam machines, and sharing actual exam content breaches the exam agreement you accept when you book an OffSec exam. Any site offering "real OSCP questions" or "dumps" is both unreliable and a policy risk. Everything below is written from OffSec's public PEN-200 syllabus so you practise the right skills ethically, on systems you own or are explicitly authorised to test.
What the OSCP and OSCP+ exam actually looks like
It is a practical exam. You get remote access to a lab network and must demonstrate control of the target machines, then submit a report. OffSec moved the modern exam to a structure that combines standalone machines with an Active Directory set.
| Item | Detail (confirm on OffSec's page before booking) |
|---|---|
| Course | PEN-200 (Penetration Testing with Kali Linux) |
| Credential | OSCP, or OSCP+ which adds a time-limited validity and continuing-education element |
| Format | Hands-on exploitation of lab machines, roughly 24 hours, followed by a report deadline |
| Score to pass | 70 points out of 100 |
| Active Directory set | An assumed-breach AD chain worth up to 40 points; pivoting may be required |
| Standalone machines | Remaining points come from standalone targets via their local and proof flags |
| Metasploit | Allowed on one target only, and not for pivoting |
The exact machine count, timings and point split are set by OffSec and change over time, so treat the numbers above as orientation and read the official OSCP exam FAQ before your sitting. The one thing that never changes: a machine that is not reported with working evidence scores nothing.
Which skills the exam tests
PEN-200's public syllabus maps to a handful of skill areas. Build a personal lab and drill each one until it is routine:
- Enumeration of ports, services and web content, including UDP, so you never miss an entry point.
- Web application testing for common flaws such as injection, file upload and authentication weaknesses.
- Service exploitation using public, well-documented vulnerabilities and how to adapt existing proof-of-concept code.
- Privilege escalation on Linux and Windows, by reading the system rather than running every script blindly.
- Active Directory attack paths: credential reuse, Kerberos abuse and lateral movement inside a test domain.
- Pivoting and tunnelling to reach segmented networks.
- Reporting: clear, reproducible steps a defender could follow to verify and fix each finding.
Practice tasks, by skill area (lab only)
Set up a lab you own, for example a few intentionally vulnerable virtual machines and a small Windows domain, or a legal training platform. Then work the tasks below. They are objectives, not an attack recipe, so you learn to find the method yourself, which is exactly what the exam rewards.
Enumeration
- Scan a host you control and produce a written inventory of every open TCP and UDP service and its version. Note which services are worth investigating first and why.
- For a web service, map the directory structure and list the technologies in use. Record what each finding might lead to.
- Write a short checklist you can reuse so your enumeration is consistent under time pressure.
Common mistake: rushing enumeration. Most stuck candidates have simply not looked hard enough at what they already found.
Web and service exploitation
- Stand up a deliberately vulnerable web app (many are published for training) and identify an injection or upload flaw. Explain the root cause and the fix, not just the exploit.
- Take a public proof-of-concept for a known CVE, read it line by line, and describe what each part does before you run it in your lab.
- Document how a defender would detect the same activity in logs. This habit sharpens both your attack notes and your report.
Privilege escalation
- On a Linux VM, enumerate users, groups, scheduled jobs, writable paths and special permissions. From that evidence, work out a realistic escalation route.
- Repeat on a Windows VM: services, scheduled tasks, privileges and misconfigurations. Tools such as enumeration scripts help, but practise reading the output yourself.
- For each route you find, write the one configuration change that would have closed it.
Active Directory and pivoting
- Build a small test domain. Practise credential discovery and reuse, then move from one host to another using only accounts you have legitimately recovered in your lab.
- Set up two network segments and practise reaching the second one through a foothold on the first, using standard tunnelling.
- Note the detection signal each step would create for a blue team, which is useful whether you go on to red or blue work.
Reporting
- Write a full report for one lab machine: scope, steps to reproduce, evidence, impact and remediation. Use OffSec's report template as your structure.
- Have a peer try to reproduce your steps from the report alone. If they cannot, your report is not finished.
A realistic study plan
Treat preparation as skill-building, not question-hunting:
- Work through the PEN-200 material and its lab machines end to end.
- Supplement with legal practice platforms and intentionally vulnerable machines you download and run yourself.
- Simulate exam conditions: a fixed time box, your own notes, and a report written the same day.
- Keep a personal methodology document and a privilege-escalation checklist for Linux and Windows.
- Rehearse time management so you move on from a stuck target and come back later.
If you want a structured path with lab access and mentoring, the OSCP (PEN-200) training with Kali Linux at WebAsha is built around this kind of hands-on practice. For the certification context and how OSCP compares to other penetration testing tracks, see our guide on CPENT and OSCP and the walkthrough on how to pass the OSCP exam on your first attempt.
Stay on the right side of the law
Only test systems you own or have written authorisation to assess. In India, unauthorised access to a computer system is an offence under the Information Technology Act, 2000. The skills on this page are for lab practice and authorised engagements, and a professional report always ends with how to fix what you found. If you are new to the field, start with the fundamentals in our penetration tester skills and certifications guide before attempting OSCP.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0