← All Certifications
OffSec

OffSec OSWA Certification

WEB-200 · Practical

Last updated: March 31, 2026

Exam Syllabus & Domains

The OffSec OSWA certification exam covers the following domains. Focus your training time proportionally to each domain's weight.

Domain 1 20%

Web Application Assessment Methodology

  • 1.1 Understand web application architecture and technologies
  • 1.2 Perform web application enumeration and mapping
  • 1.3 Use proxy tools for traffic interception and analysis
  • 1.4 Apply systematic testing methodology to web applications
HTTP ProtocolRequest/Response CycleBurp Suite ProxyWeb Application MappingTechnology FingerprintingCookie AnalysisSession ManagementOWASP Testing GuideDeveloper ToolsAPI Enumeration
Domain 2 20%

Cross-Site Scripting (XSS)

  • 2.1 Identify and exploit reflected XSS vulnerabilities
  • 2.2 Discover and exploit stored XSS vulnerabilities
  • 2.3 Exploit DOM-based XSS vulnerabilities
  • 2.4 Bypass XSS filters and content security policies
Reflected XSSStored XSSDOM-Based XSSXSS Filter BypassContent Security PolicyCookie TheftSession HijackingJavaScript PayloadsHTML InjectionEvent Handlers
Domain 3 25%

SQL Injection

  • 3.1 Identify SQL injection points in web applications
  • 3.2 Perform UNION-based and error-based SQL injection
  • 3.3 Execute blind SQL injection techniques (boolean and time-based)
  • 3.4 Extract data and escalate access through SQL injection
UNION-Based SQLiError-Based SQLiBoolean Blind SQLiTime-Based Blind SQLiSecond-Order SQLisqlmap UsageDatabase EnumerationData ExfiltrationWAF BypassPrepared Statements
Domain 4 20%

Authentication & Session Attacks

  • 4.1 Identify authentication vulnerabilities and bypass techniques
  • 4.2 Attack session management mechanisms
  • 4.3 Exploit insecure password reset and recovery flows
  • 4.4 Perform credential-based attacks against web applications
Authentication BypassBrute Force AttacksSession FixationSession HijackingJWT AttacksOAuth VulnerabilitiesPassword Reset FlawsCSRF AttacksCredential StuffingMulti-Factor Bypass
Domain 5 15%

Server-Side Attacks & File Inclusion

  • 5.1 Exploit local and remote file inclusion vulnerabilities
  • 5.2 Perform server-side request forgery (SSRF) attacks
  • 5.3 Exploit insecure file upload functionality
  • 5.4 Identify and exploit command injection vulnerabilities
Local File InclusionRemote File InclusionSSRF AttacksFile Upload ExploitsCommand InjectionPath TraversalWeb Shell UploadPHP WrappersLog PoisoningXXE Injection

Where to Focus Your Study Time

Domains with higher weight have more exam questions — allocate your study hours accordingly.

D1 Web Application Assessment Methodology
20%
D2 Cross-Site Scripting (XSS)
20%
D3 SQL Injection
25%
D4 Authentication & Session Attacks
20%
D5 Server-Side Attacks & File Inclusion
15%

Study Tips

Free Study Resources

๐Ÿ“‹

Study Roadmap

Week-by-week study plan with free resources

โœ…

Study Tracker

Track objective completion with progress dashboard

๐Ÿ’ฐ

Cost Calculator

Total cost breakdown and ROI analysis

๐Ÿงช

Practice Quiz

Test your knowledge with free practice questions

Practice Quiz

Test your knowledge before the exam with our free practice quiz.

Take the OffSec OSWA Practice Quiz

Get the OffSec OSWA Study Planner

Fillable PDF with 12-week schedule, domain trackers, flashcard templates, progress tracking, and quick reference sheets. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

Get the Study Planner — $5.99

Also available as a 4-Format Bundle for $15.99

CyberFolio

Earned your certs? Show employers.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →

Free Training Resources

Use these free tools to support your OffSec OSWA certification training:

Frequently Asked Questions

What is the OffSec OSWA certification?

The OffSec OSWA (WEB-200) is a professional IT certification that validates your knowledge and skills in the exam domains covered. It is recognized globally by employers and is a valuable credential for career advancement in cybersecurity and IT.

What does the OffSec OSWA certification syllabus cover?

The OffSec OSWA exam syllabus covers Practical. Each domain is weighted differently, so focus your training on higher-weighted domains first. Review the complete domain breakdown above for objectives and key concepts.

How should I study for OffSec OSWA?

Create a structured study plan covering all exam domains, use practice tests to identify weak areas, and review key concepts regularly. A fillable study planner can help you organize your training with weekly schedules and progress tracking.

How long does it take to prepare for OffSec OSWA?

Preparation time varies by experience level. Most candidates spend 8-12 weeks of dedicated training. Using a structured study planner with domain-by-domain breakdown helps ensure you cover all certification objectives efficiently.