Prepare for the Offensive Security Certified Professional (OSCP) certification by OffSec with free exam-style practice questions on CyberCertPrep. The OSCP exam has 100 questions, a time limit of 24 hours, and a passing score of 70%.
Choose from Practice mode, Knowledge Readiness, Weak Areas review, and Daily Challenge. Track your progress with detailed analytics and study with flashcards.
Offensive Security Certified Professional (OSCP) Exam Domain
Focus your study on this domain with targeted practice questions. This domain accounts for 10% of your OSCP exam score.
The Exploit Development & Buffer Overflows domain is one of 7 exam domains on the Offensive Security Certified Professional (OSCP) certification exam by OffSec. At 10% of the total exam, this domain is important but should be balanced with higher-weighted domains in your study plan.
The OSCP exam consists of 100 questions with a time limit of 24 hours and a passing score of 70%. That means approximately 10 questions on your exam will come from the Exploit Development & Buffer Overflows domain.
Privilege Escalation
An attack where a user gains elevated access to resources that are normally protected, beyond what their assigned permis...
SQL Injection
A code injection technique that exploits vulnerabilities in a web application's database layer by inserting malicious SQ...
Social Engineering
The psychological manipulation of people into performing actions or divulging confidential information, exploiting human...
Zero-Day Exploit
An attack that targets a previously unknown vulnerability in software, hardware, or firmware before the vendor has relea...
Buffer Overflow
A vulnerability that occurs when a program writes more data to a memory buffer than it can hold, causing adjacent memory...
Risk Assessment
The process of identifying, analyzing, and evaluating potential risks to an organization's information assets to determi...
Vulnerability Assessment
A systematic process to identify, quantify, and prioritize security vulnerabilities in systems, applications, and networ...
Penetration Testing
An authorized simulated cyberattack on a computer system, network, or application performed to evaluate its security pos...
These certifications also cover topics related to Exploit Development & Buffer Overflows:
Software Development Security, 10% of exam
IS Acquisition, Development and Implementation, 12% of exam
AI Development & Lifecycle, 25% of exam
Computer & Network Hacker Exploits, 25% of exam
RAG and Embedding Exploitation, 18% of exam
Attacks and Exploits, 35% of exam