200+ Free OSWE Practice Questions
Pass your OSWE OffSec Web Expert (WEB-300) exam on the first try — instant access, no signup required.
When reproducing a suspected blind SQL injection in a login workflow, which Burp Suite tool is usually best for sending one request at a time while changing a single parameter and watching the response?
Key Facts: OSWE Exam
4
Scored Objectives
OffSec exam guide
85/100
Passing Score
OffSec exam guide
47h 45m
Exam Time
OffSec exam guide
24 hours
Report Upload Window
OffSec FAQ / proctoring article
17
Syllabus Modules
OffSec WEB-300 page
20
Challenge Labs
OffSec WEB-300 page
As of March 11, 2026, OffSec's OSWE exam remains a 47-hour-45-minute practical with 4 objectives worth 25 points each and an 85/100 passing score. Candidates then have 24 hours to upload their report. OffSec currently allows notes and online resources during the open-book exam, but the FAQ explicitly excludes AI chatbots and LLMs with direct prompt access.
Sample OSWE Practice Questions
Try these sample questions to test your OSWE exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 200+ question experience with AI tutoring.
1When reproducing a suspected blind SQL injection in a login workflow, which Burp Suite tool is usually best for sending one request at a time while changing a single parameter and watching the response?
2A request only becomes exploitable after the application sets a CSRF token in a hidden form field. What should you capture first in Burp before sending crafted payloads to Repeater?
3You obtain a deployed ASP.NET application and need to inspect server-side logic quickly. Which approach is most aligned with WEB-300 methodology?
4A Java web application ships as a WAR file with many `.class` files but no source. What is the most useful next step for white-box review?
5Why is remote debugging valuable when a suspected code path is complex and controlled by multiple conditions?
6A password reset flow reveals whether a user exists by returning different HTML lengths for valid and invalid accounts. What is the main attacker advantage?
7In boolean-based blind SQL injection, why do testers often compare full response bodies rather than relying only on the HTTP status code?
8A file upload filter blocks `.php` files but accepts image uploads. Which server-side mistake most commonly makes a bypass possible?
9An upload handler strips one dangerous extension but then saves the original basename plus the remaining suffix. Which filename is most likely to succeed if the handler only removes the first occurrence of `.php`?
10After obtaining code execution in a restricted web shell, you need a more stable foothold. What information is usually most valuable to gather first?
About the OSWE Exam
OSWE is OffSec's advanced web exploitation certification tied to WEB-300: Advanced Web Attacks and Exploitation. The exam is a long-form, open-book, remotely proctored practical that expects candidates to analyze source code, chain complex web vulnerabilities, develop reliable exploits, retrieve proof, and submit a professional report.
Assessment
4 hands-on objectives worth 25 points each, plus required report submission
Time Limit
47h 45m exam + 24h report upload window
Passing Score
85/100
Exam Fee
$1,749 Course + Cert Bundle or $2,749/year Learn One (OffSec)
OSWE Exam Content Outline
Tooling, Source Recovery, and Debugging
Burp workflow, Python interaction, source-code recovery, routing analysis, IDE use, and remote debugging. OffSec does not publish official percentages; this weighting is inferred from the current WEB-300 syllabus.
Authentication Bypass and Logic Flaws
Broken reset flows, weak token generation, session abuse, CORS/CSRF chaining, insecure defaults, and application logic mistakes.
Injection and Data Exfiltration
Blind SQL injection, SQLi-assisted account takeover, data extraction, file-upload bypass, command injection, and database-to-RCE thinking.
Deserialization, Type Confusion, and SSTI
PHP loose comparison, magic hashes, .NET deserialization, object-graph abuse, template injection discovery, and filter evasion.
XXE, SSRF, and Server-Side Chaining
XML parser abuse, blind SSRF enumeration, API discovery, microservice pivoting, and internal-service exploitation.
Client-Side and JavaScript Attack Chains
Persistent or DOM-based XSS, JavaScript source analysis, WebSocket abuse, prototype pollution, and template-engine RCE paths.
Custom Exploitation and Reporting
Choosing stable exploit paths, writing reproducible proof-of-concept code, collecting evidence, and documenting every objective clearly.
How to Pass the OSWE Exam
What You Need to Know
- Passing score: 85/100
- Assessment: 4 hands-on objectives worth 25 points each, plus required report submission
- Time limit: 47h 45m exam + 24h report upload window
- Exam fee: $1,749 Course + Cert Bundle or $2,749/year Learn One
Keys to Passing
- Complete 500+ practice questions
- Score 80%+ consistently before scheduling
- Focus on highest-weighted sections
- Use our AI tutor for tough concepts
OSWE Study Tips from Top Performers
Frequently Asked Questions
What is the OSWE exam format?
OffSec's current OSWE exam guide states that WEB-300 candidates have 47 hours and 45 minutes to complete the exam and that the exam contains 4 objectives worth 25 points each. The guide also states that you must score 85 points to pass. After the practical ends, OffSec gives you another 24 hours to upload your report.
How many questions are on the OSWE exam?
OSWE is not a multiple-choice exam. OffSec currently describes it as a hands-on practical with 4 scored objectives rather than a bank of conventional questions. This practice set provides 200 multiple-choice items to help you rehearse the knowledge and reasoning behind the live exam.
Does OffSec publish official OSWE domain percentages?
As of March 11, 2026, I did not find official percentage weightings for OSWE on OffSec's current WEB-300 course page, syllabus, exam guide, or FAQ. The content sections on this page are therefore inferred from the published WEB-300 syllabus topics and the exam objectives OffSec does describe publicly.
Is OSWE open book, and can I use AI during the exam?
The current OSWE FAQ says the exam is open book and that you may use your notes, online resources, and the OffSec Learning Platform. The same FAQ also explicitly excludes AI chatbots and LLMs with direct prompt access, so you should treat interactive AI assistance as off-limits during the active exam.
How much does the OSWE exam cost in 2026?
The current public WEB-300 page shows pricing starting at $1,749 for the Course + Cert Bundle, while OffSec's current products page lists Learn One at $2,749 per year. OffSec's OSWE pages do not currently show a separate public OSWE standalone-exam listing similar to OSCP+, so the most visible public purchase paths are the training bundle and Learn One subscription.
What changed for OSWE in 2026?
As of March 11, 2026, I did not find a new OSWE-specific overhaul notice comparable to OffSec's separate OSCP+ change announcements. The current official OSWE materials still describe WEB-300/OSWE as a 48-hour-class practical path, and the most relevant current policy language is the FAQ's explicit ban on AI chatbots and direct-prompt LLM use during the open-book exam.