Exam Domains
1 Source Code Review and Authentication Bypass
Weight not published
2 SQL Injection via Source Code Analysis
Weight not published
3 Server-Side Request Forgery (SSRF)
Weight not published
4 OS Command Injection
Weight not published
5 XML External Entity (XXE) Injection
Weight not published
6 Deserialization Vulnerabilities
Weight not published
7 Cross-Site Scripting (XSS) and Prototype Pollution
Weight not published
8 Exploit Chaining and Report Writing
Weight not published
Exam Details
Question TypesPractical/Hands-On (exploit vulnerable machines, submit proof.txt files)
FormatPractical / Penetration Test Lab
Online ProctoringAvailable
ID RequirementsValid government-issued photo ID shown to proctor via webcam at exam start.
RenewalNot required -- OffSec certifications do not expire.
PrerequisitesOSCP or equivalent web application security experience (recommended)
Retake PolicyRetake attempts can be purchased separately. No mandatory waiting period. Retake pricing varies by course bundle.
LanguagesEnglish