Frequently Asked Questions
Last updated
Was this helpful?
Last updated
Was this helpful?
For the AD Section, PEN-200 mostly covers all the contents required to pass the OSCP Certification. These lab environments ( LOCAL, THM, HTB ) are totally up to your preference. If you are interested in completing the HTB Machines from TJNull's machine list, you would need an HTB Subscription which costs around 10/15 Pounds per month based on your preference.
Yes, you are allowed to use modernized tools. The tools which I used during my exams are ffuf, feroxbuster, autorecon, and nikto some manually scripted tools. However, you are not allowed to use commercial tools such as Burpsuite Professional and Metasploit Profession, etc., More can be found here
NO, Connection to the labs is to be done using Kali Linux only.
Yes, But only once. I would suggest using Metasploit only when you find yourselves in a position where you cannot exploit the vulnerability manually. But you cannot use Metasploit for pivoting and stuffs like that
Do I need an Admin/root shell to get full marks?
No, You may not need an Administrator shell in the windows box for sure, But you must need either the following, source
Contact orders@offensive-security.com. Ask them about the procedures and provide the documents they require.
Offensive Security does offer discounts to people in need. Individuals who are unemployed and not enrolled in post-secondary education may be eligible.
Sure, you are not restricted by any means. Since they are public exploits
I have tried cherrynote, onenote, EverNote, Joplin, vscode, and obsidian. But obsidian seems to be my fit with its vast plugins and themes.
I have been passively preparing for almost 4 Years. And actively for 2 months.
I completed around 64machines from Hackthebox, 71 rooms from Tryhackme, and 27 machines from OSCP labs
These counts were upto the time when I took the OSCP examination
I don't know much since I completed only 27 machines but In the public networks, there are 2 AD sets which I would recommend you to complete first. Also, make use of the offsec forums whenever you feel stuck.
I just followed the Learning path by offsec. I did go through the machines in order. The learning path can be found here
I used the default word template provided by offsec(here)
Sure, here it is
I really cant comment on that, cause I was not able to afford the course. I don't know what was in the course. I opted for openly available resources which helped me to pass the certification. The resources I have used are mentioned above
I had no issues with that, the proctors have asked me to show them around the room and instructed me to remove any other electronic devices which were not in the use for examination ( cellphones )
It's Unlimited, you can take breaks whenever you want how long you want
Learn the contents in the PWK Course materials, that's more than enough
Like they said in the exam change, I got 3 standalone machines ( Windows, Linux, and BufferOverflow Machine) and an AD set (2 Clients and 1 Domain Controller )
Was the buffer overflow easy?
It's with ease difficulty if you follow the mentioned resource and understand it. However, exploiting buffer overflow will not provide you the shell as NT Authority \ root as it previously did. After successfully exploiting the buffer overflow the shell as the user will be obtained and you are still needed to perform privilege escalation
When you logged into the exam panel, you will be provided with the summary of the machines which summarizes the machine details so you will know about the buffer overflow machine. You will also be provided with the RDP Connection to the development machine.
I managed to secure 70 points within 12 hours span.
You will be allowed to access the exam machines for 23 hours and 45 minutes. And you will get another 24 hours from the end of your exam to submit your report
To obtain the bonus 10 points, you must complete the following and make a report of it
No, I did not complete the course exercise
Yeah, of course. The enumeration with good enumerating skills you can complete the exam with ease