The OffSec OSCP certification validates your expertise and opens doors to higher-paying roles in IT and cybersecurity. Whether you are just starting your study journey or doing a final review, this guide breaks down everything you need to know to pass the PEN-200 exam.
Exam Overview
- Certification: OffSec OSCP
- Exam Code: PEN-200
- Vendor: OffSec
- Cost: $1,749 USD (course + exam)
- Duration: 23 hours 45 minutes + report
- Questions: Hands-on practical exam
- Passing Score: 70 out of 100 points
- Format: Hands-on penetration testing with written report
- Prerequisites: Networking & Linux fundamentals recommended
Domain Breakdown
Understanding the exam domains and their weights is critical for efficient study planning. Focus more time on heavily-weighted domains while ensuring you cover all areas.
Domain 1: Penetration Testing Fundamentals (15%)
- 1.1 Understand penetration testing methodology and rules of engagement
- 1.2 Set up and configure Kali Linux attack environment
- 1.3 Apply effective note-taking and documentation practices
- 1.4 Understand legal and ethical considerations in penetration testing
Key concepts: Pentest Methodology, Rules of Engagement, Kali Linux, Bash Scripting, Report Writing, Scope Definition, Legal Considerations, Note-Taking Tools
Domain 2: Information Gathering & Enumeration (20%)
- 2.1 Perform passive and active information gathering techniques
- 2.2 Enumerate services including DNS, SMB, SNMP, and HTTP
- 2.3 Conduct vulnerability scanning and analysis
- 2.4 Identify and prioritize attack vectors from enumeration data
Key concepts: Nmap Scanning, DNS Enumeration, SMB Enumeration, SNMP Enumeration, Web Enumeration, Directory Brute-Forcing, Vulnerability Scanning, Service Fingerprinting
Domain 3: Web Application Attacks (20%)
- 3.1 Identify and exploit common web vulnerabilities
- 3.2 Perform SQL injection attacks including blind and UNION-based
- 3.3 Exploit file inclusion vulnerabilities (LFI/RFI)
- 3.4 Attack web applications through XSS, command injection, and file upload
Key concepts: SQL Injection, Cross-Site Scripting, Command Injection, Local File Inclusion, Remote File Inclusion, File Upload Attacks, Directory Traversal, Web Shells
Domain 4: System Exploitation & Privilege Escalation (20%)
- 4.1 Exploit Windows and Linux systems using public and custom exploits
- 4.2 Perform Windows privilege escalation techniques
- 4.3 Perform Linux privilege escalation techniques
- 4.4 Transfer files and establish reverse/bind shells
Key concepts: Buffer Overflows, Windows Priv Esc, Linux Priv Esc, SUID/SGID Exploits, Kernel Exploits, Token Impersonation, Service Exploits, Reverse Shells
Domain 5: Active Directory Attacks (15%)
- 5.1 Enumerate Active Directory environments and trust relationships
- 5.2 Perform AD attacks including Kerberoasting and AS-REP roasting
- 5.3 Execute lateral movement techniques across the domain
- 5.4 Achieve domain dominance through credential-based attacks
Key concepts: AD Enumeration, Kerberoasting, AS-REP Roasting, Pass-the-Hash, Pass-the-Ticket, Lateral Movement, BloodHound, Mimikatz
Domain 6: Post-Exploitation & Reporting (10%)
- 6.1 Perform post-exploitation data gathering and exfiltration
- 6.2 Establish persistence and maintain access
- 6.3 Pivot through compromised hosts to reach internal networks
- 6.4 Write professional penetration testing reports
Key concepts: Port Forwarding, SSH Tunneling, Pivoting, Persistence Mechanisms, Data Exfiltration, Antivirus Evasion, Chisel/Ligolo, Report Structure
Recommended Study Timeline
Plan for approximately 10-16 weeks of dedicated study. Here is a suggested weekly breakdown:
- Week 1: Domain 1: Pentest methodology, Kali Linux setup, bash scripting, report templates
- Week 2: Domain 2: Passive recon — OSINT, Google dorking, Whois, DNS enumeration
- Week 3: Domain 2: Active scanning — Nmap, service enumeration, SMB/SNMP/HTTP
- Week 4: Domain 3: Web attacks — SQL injection (UNION, blind, error-based), sqlmap
- Week 5: Domain 3: Web attacks — LFI/RFI, XSS, command injection, file uploads
- Week 6: Domain 4: Windows exploitation — Buffer overflows, public exploits, Metasploit
- Week 7: Domain 4: Windows privilege escalation — Token impersonation, service exploits, unquoted paths
- Week 8: Domain 4: Linux exploitation & privilege escalation — SUID, cron, kernel exploits, capabilities
- Week 9: Domain 5: Active Directory — Enumeration, BloodHound, Kerberoasting, AS-REP roasting
- Week 10: Domain 5: AD lateral movement — Pass-the-hash, pass-the-ticket, Mimikatz, domain persistence
- Week 11: Domain 6: Post-exploitation — Pivoting, port forwarding, SSH tunneling, Chisel/Ligolo
- Week 12: Lab Practice: Work through OSCP lab machines, document methodology
- Week 13: Lab Practice: Challenge labs, timed exercises, try harder machines
- Week 14: Lab Practice: Full mock exam — 5 machines in 24 hours with report
- Week 15: Report Writing: Practice professional report writing, refine templates
- Week 16: Final Review: Weak areas, exam strategy, rest and preparation
Top Study Tips
- Start with the official exam objectives. Download them from the OffSec website and use them as your study checklist. Every exam question maps to a specific objective.
- Use active recall over passive reading. Instead of re-reading notes, test yourself with practice questions after each study session. This dramatically improves retention.
- Focus on heavily-weighted domains first. Domains with higher percentages appear more on the exam. Master these before moving to lower-weighted areas.
- Build hands-on experience. Set up a lab environment and practice the skills you are studying. Hands-on experience is especially valuable for performance-based questions.
- Take practice exams under real conditions. Time yourself, eliminate distractions, and simulate the exam environment. Review every wrong answer and understand why it was wrong.
Practice Resources
Test your knowledge with our free tools:
Take our free OffSec OSCP practice quiz
- CVSS Calculator — Practice scoring vulnerabilities
- Password Strength Checker — Test password security
Career Impact
The OffSec OSCP certification demonstrates validated expertise to employers. Certified professionals typically see:
- Higher starting salaries compared to non-certified peers
- More interview callbacks as the certification signals commitment and competence
- Faster career progression with a recognized credential on your resume
- Access to roles that specifically require or prefer OffSec OSCP certification
What to Study Next
After earning your OffSec OSCP certification, consider these natural next steps:
- Deepen your specialization with an advanced certification in the same vendor track
- Broaden your skills with a certification from a complementary domain
- Visit our Career Paths page for detailed certification roadmaps
Get Organized with a Study Planner
A structured study plan makes the difference between passing and failing. Our fillable PDF study planners include domain trackers, weekly schedules, and progress tracking designed specifically for OffSec OSCP exam prep.
This guide is independently created for educational purposes. OffSec trademarks belong to their respective owners. FixTheVuln is not affiliated with or endorsed by OffSec.
Explore More
Exam Syllabus & Domain Breakdown
Review the complete certification syllabus, domain weights, and free training resources.
View Full Certification Guide →FixTheVuln Store
OSCP Prep? Get the Study Planner
Structured planner for OffSec certifications. Exploitation methodology, lab trackers, and reporting templates.
Shop OSCP PlannerAlso available: OSCP, OSWA, OSWE
CyberFolio
Building cybersecurity skills? Track them in one place.
Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.
Build Your Portfolio →