Prepare for the OffSec Web Expert (OSWE) certification by OffSec with free exam-style practice questions on CyberCertPrep. The OSWE exam has 100 questions, a time limit of OSWE hours, and a passing score of 70%.
Choose from Practice mode, Exam Simulation, Weak Areas review, and Daily Challenge. Track your progress with detailed analytics and study with flashcards.
OffSec Web Expert (OSWE) Exam Domain
Focus your study on this domain with targeted practice questions. This domain accounts for 25% of your OSWE exam score.
The Source Code Analysis domain is one of 4 exam domains on the OffSec Web Expert (OSWE) certification exam by OffSec. At 25% of the total exam, this is one of the most heavily weighted domains — mastering it is critical for passing.
The OSWE exam consists of 100 questions with a time limit of 48 hours and a passing score of 70%. That means approximately 25 questions on your exam will come from the Source Code Analysis domain.
Access Control List (ACL)
A list of permissions attached to an object that specifies which users or system processes are granted access to resourc...
Authentication
The process of verifying the identity of a user, device, or system before granting access to resources. Authentication t...
Authorization
The process of determining what resources or actions an authenticated user is permitted to access. While authentication ...
Zero Trust
A security model that requires strict identity verification for every person and device attempting to access resources, ...
Privilege Escalation
An attack where a user gains elevated access to resources that are normally protected, beyond what their assigned permis...
VPN (Virtual Private Network)
A technology that creates a secure, encrypted connection (tunnel) over a less secure network such as the internet, allow...
IDS (Intrusion Detection System)
A device or software application that monitors a network or systems for malicious activity or policy violations and gene...
IPS (Intrusion Prevention System)
A network security tool that monitors network traffic flows to detect and actively prevent identified threats in real ti...
These certifications also cover topics related to Source Code Analysis:
Risk Identification, Monitoring & Analysis — 15% of exam
Traffic Analysis & Protocols — 25% of exam
Packet Analysis & Monitoring — 25% of exam
Tools & Code Analysis — 16% of exam
Shellcode & Return-Oriented Programming — 25% of exam
Custom Shellcode — 25% of exam