All Practice Exams

100+ Free PORP Practice Questions

Prepare for the TCM Security Practical OSINT Research Professional exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: PORP Exam

$399

Exam Cost (includes retake + training)

TCM Security

72 hours

Practical Engagement Window

TCM Security

80/100

Passing Score

TCM Security

No MCQ

Fully Practical — Report-Based

TCM Security

No expiry

Certification Does Not Expire

TCM Security

1 free

Retake Included

TCM Security

The PORP from TCM Security is a practical OSINT certification covering 6 domains: OSINT Methodology (15%), SOCMINT & Account Pivoting (20%), People & Identity Investigation (20%), Domain & Website OSINT (20%), GEOINT & Business Intelligence (15%), and Reporting & Source Triangulation (10%). The exam gives 72 hours to complete a real-world OSINT engagement and submit a professional report. Passing score is 80/100. Cost is $399 with one free retake and 12 months of TCM Academy course access. Primary prep: TCM Security OSINT Fundamentals course. This practice exam covers conceptual knowledge; actual PORP requires hands-on OSINT research.

Sample PORP Practice Questions

Try these sample questions to test your PORP exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Which of the following best describes the core purpose of Open-Source Intelligence (OSINT)?
A.Collecting and analyzing information from publicly available sources to produce actionable intelligence
B.Intercepting encrypted network traffic using passive sniffers
C.Performing social engineering calls to extract credentials
D.Exploiting vulnerabilities in publicly exposed web services
Explanation: OSINT is the practice of gathering, analyzing, and synthesizing information from publicly available, legally accessible sources — such as websites, social media, public records, and databases — to produce actionable intelligence. It does not involve unauthorized access, interception, or active exploitation.
2In the OSINT intelligence cycle, which phase involves transforming raw collected data into a usable intelligence product?
A.Planning and direction
B.Processing and analysis
C.Dissemination
D.Collection
Explanation: The processing and analysis phase transforms raw collected data — URLs, screenshots, usernames, phone numbers — into organized, evaluated intelligence. Collection gathers the raw data; planning sets objectives; dissemination delivers the finished product to stakeholders.
3A PORP investigator wants to search for a specific phrase across indexed web pages. Which Google search operator limits results to pages containing the exact phrase?
A.intitle:target phrase
B.phrase:target phrase
C."target phrase"
D.exact:target phrase
Explanation: Enclosing a phrase in double quotes instructs Google to return only pages containing that exact sequence of words. The `intitle:` operator searches within page titles only; there is no `phrase:` or `exact:` Google operator.
4Which Google dork would an investigator use to find all indexed pages on the domain example.com that contain the word 'password'?
A.domain:example.com password
B.host:example.com "password"
C.site:example.com AND password
D.site:example.com intext:password
Explanation: The `site:` operator restricts results to a specific domain, and `intext:` searches the body text of pages. Combining `site:example.com intext:password` returns only pages on example.com that contain the word 'password' in their body text — a standard Google dorking pattern.
5What is a 'sock puppet' account in the context of OSINT investigations?
A.A fabricated online persona created to conduct covert research without revealing the investigator's identity
B.A compromised account used by threat actors to exfiltrate data
C.A secondary backup account required by some platforms for two-factor authentication
D.An automated bot account used to flood social media with disinformation
Explanation: A sock puppet is a fictitious online persona created by an investigator to conduct covert OSINT research — for example, to view social media profiles that require account login without alerting the subject. Proper sock puppet hygiene includes using a VPN, separate device, and fictitious email and profile photo.
6An investigator retrieves EXIF metadata from a JPEG photo posted online. Which piece of metadata is most useful for geolocation?
A.ColorSpace value
B.GPS coordinates embedded in the GPSLatitude and GPSLongitude tags
C.Camera model stored in the Make and Model tags
D.Image resolution in the XResolution and YResolution tags
Explanation: EXIF GPS tags (GPSLatitude, GPSLongitude, GPSLatitudeRef, GPSLongitudeRef) store precise geographic coordinates captured by GPS-enabled cameras and smartphones. Tools like ExifTool parse these tags to reveal where a photo was taken. Most major social platforms strip GPS EXIF data on upload, but investigator-obtained originals often retain it.
7Which tool is specifically designed for reverse image searching to identify where a photo has appeared online?
A.Shodan
B.theHarvester
C.Google Lens (or TinEye / Yandex Images)
D.Maltego
Explanation: Reverse image search engines such as Google Lens, TinEye, and Yandex Images allow investigators to upload or paste an image URL to find where it has appeared online — useful for identifying subjects, verifying profile photos, and detecting sock puppet reuse. Shodan scans internet-connected devices; theHarvester gathers emails/subdomains; Maltego builds relationship graphs.
8What does SOCMINT stand for, and what is its primary data source?
A.Source Code Management Intelligence; version control repositories
B.Social Commerce Intelligence; e-commerce transaction data
C.Security Operations Center Management Intelligence; corporate SIEM logs
D.Social Media Intelligence; publicly accessible social media platforms and user-generated content
Explanation: SOCMINT (Social Media Intelligence) is the collection and analysis of information derived from social media platforms — Twitter/X, Facebook, Instagram, LinkedIn, Reddit, TikTok, etc. — and other user-generated content. It is a critical sub-discipline of OSINT for people profiling, event monitoring, and network mapping.
9When investigating a Twitter/X account, which URL format allows an investigator to view all tweets from a specific user mentioning a keyword using the advanced search?
A.twitter.com/search?q=from:username keyword
B.twitter.com/username/search/keyword
C.twitter.com/advanced?user=username&q=keyword
D.twitter.com/lookup?handle=username&term=keyword
Explanation: Twitter/X advanced search supports the `from:username keyword` query syntax to return all tweets from a specified account that contain the keyword. This can be entered in the search bar or as URL parameters. The other URL formats do not exist in the Twitter/X platform.
10An investigator needs to find cached versions of a now-deleted Instagram profile. Which tool or service is best suited for this?
A.Shodan
B.The Wayback Machine (web.archive.org)
C.Censys
D.SpiderFoot HX
Explanation: The Wayback Machine (archive.org) crawls and archives web pages, including social media profiles. An investigator can enter a deleted Instagram profile URL to find historical snapshots. However, Instagram profiles are inconsistently archived — Google's cache and specialized social OSINT tools may also help. Shodan and Censys focus on internet-connected infrastructure, not social profiles.

About the PORP Exam

The PORP (Practical OSINT Research Professional) is TCM Security's certification validating real-world open-source intelligence gathering and reporting skills. Unlike multiple-choice exams, the PORP requires conducting a 72-hour practical OSINT engagement against a real-world simulation, then submitting a professional written report. This practice test covers the theoretical knowledge underpinning the exam: SOCMINT, people and identity investigation, domain OSINT, GEOINT, business intelligence, dark web awareness, and structured OSINT reporting.

Assessment

Performance-based assessment

Time Limit

72 hours (3 days) for OSINT engagement + report submission

Passing Score

80/100 points

Exam Fee

$399 (includes one free retake and 12 months TCM Academy access) (TCM Security)

PORP Exam Content Outline

20%

SOCMINT & Account Pivoting

Social media intelligence across major platforms (Twitter/X, LinkedIn, Facebook, Instagram, Reddit), username pivoting with Sherlock and WhatsMyName, footprint mapping, profile correlation, and monitoring public social activity patterns

20%

People & Identity Investigation

Public records research, email OSINT with Hunter.io and Emailrep, phone number lookup with Truecaller and NumLookup, breached data analysis with HaveIBeenPwned, and cross-platform identity verification

20%

Domain & Website OSINT

WHOIS and registrar research, certificate transparency with crt.sh, Wayback Machine and archive.org analysis, DNS enumeration, subdomain discovery with dnsx/subfinder, technology fingerprinting with Wappalyzer, and website intelligence gathering

15%

OSINT Methodology & Process

Intelligence cycle (planning, collection, processing, analysis, dissemination), OSINT frameworks (OSINT Framework site), pivot strategies, source credibility evaluation, structured analytic techniques, and search engine dorking with Google, Bing, and Yandex

15%

GEOINT & Business Intelligence

Reverse image search with TinEye and Google Lens, geolocation using Google Maps Street View and satellite imagery, Yandex reverse image, business registration records, corporate structure mapping, and wireless network OSINT with Wigle.net

10%

Reporting & Source Triangulation

Professional OSINT report writing, note-keeping with tools like Obsidian and CherryTree, triangulating findings across multiple independent data sources, dark web awareness (Tor, Ahmia) without active engagement, and proper source attribution in written deliverables

How to Pass the PORP Exam

What You Need to Know

  • Passing score: 80/100 points
  • Assessment: Performance-based assessment
  • Time limit: 72 hours (3 days) for OSINT engagement + report submission
  • Exam fee: $399 (includes one free retake and 12 months TCM Academy access)

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

PORP Study Tips from Top Performers

1Master advanced Google dorking operators (site:, filetype:, inurl:, intitle:, cache:) — search engine proficiency is the foundation of effective OSINT
2Practice username pivoting with Sherlock and WhatsMyName across dozens of platforms to map a subject's full digital footprint
3Learn to use crt.sh certificate transparency logs to discover subdomains and historical infrastructure not visible in WHOIS
4Develop a consistent note-keeping workflow with tools like Obsidian or CherryTree before the exam — you cannot effectively report what you did not document
5Practice reverse image searching with TinEye, Google Lens, AND Yandex — each returns different results for the same image
6Understand the Wayback Machine's CDX API for programmatic historical URL discovery beyond what the web interface shows
7Always triangulate findings across at least three independent sources before including them in a professional OSINT report
8Learn Wigle.net for wireless OSINT — BSSID and SSID lookups can geolocate a device's historical network associations
9Practice structuring OSINT reports with clear methodology, source citations, confidence levels, and actionable findings — the report is what gets graded
10Build awareness of dark web resources (Ahmia, Tor) conceptually for the exam without actively engaging in unlawful activity

Frequently Asked Questions

What is the PORP exam format?

The PORP gives candidates 72 hours (3 days) to conduct a practical OSINT engagement based on real-world simulation challenges. There are no multiple-choice questions — your performance depends entirely on your research skills, source triangulation, and professional report quality. You gather intelligence from social media, public records, online databases, and other open sources, then submit a written report. The exam is scored out of 100 points, with 80 required to pass. One free retake is included with the $399 purchase.

What OSINT tools and techniques are covered in the PORP?

The PORP covers a wide range of OSINT tools and techniques: Google/Bing/Yandex advanced search operators and dorking; Sherlock and WhatsMyName for username OSINT; Hunter.io and HaveIBeenPwned for email and breach data; crt.sh for certificate transparency; WHOIS and DNS lookup tools; Wayback Machine for historical website data; TinEye, Google Lens, and Yandex for reverse image search; Google Maps Street View and satellite imagery for geolocation; Wigle.net for wireless network OSINT; and structured note-keeping and report writing workflows.

How does PORP compare to other OSINT certifications?

The PORP ($399) is TCM Security's practical OSINT certification and stands out for its real-world hands-on engagement format rather than multiple-choice testing. It is more affordable and beginner-friendly than many competing credentials. The 72-hour window and professional report requirement ensure candidates demonstrate genuine research skills. Other OSINT-adjacent certifications include Trace Labs CTF events and SANS FOR578 (cyber threat intelligence), but these target different audiences and price points. PORP is the most accessible starting point for aspiring OSINT analysts.

What courses should I take to prepare for the PORP?

TCM Security's OSINT Fundamentals course is the primary recommended preparation — it covers search engine OSINT, image and email OSINT, people and phone OSINT, website and social media OSINT, wireless network OSINT, and report writing. The $399 PORP package includes 12 months of TCM Academy access. TCM Security has also offered live 'Introduction to OSINT' training sessions that align directly with exam content. Practicing on Trace Labs CTF events and OSINT Challenge sites builds practical research speed.

What jobs can I get with the PORP certification?

The PORP validates skills relevant to roles including: OSINT Analyst, Threat Intelligence Analyst, Investigations Analyst, Corporate Due Diligence Researcher, Social Media Intelligence (SOCMINT) Analyst, Fraud Investigator, and Competitive Intelligence Researcher. It is also highly relevant for law enforcement, private investigators, and security researchers. Combined with other TCM certifications like PNPT, it strengthens profiles for holistic penetration tester and red team roles that include reconnaissance phases.

Is this practice exam like the real PORP?

No — this is a theoretical multiple-choice knowledge exam. The real PORP is a 72-hour hands-on practical engagement where you must actively research a target using open sources and write a professional report. Use this practice exam to test your understanding of OSINT tools, techniques, and methodology. To pass the actual PORP, you must practice hands-on OSINT research using the TCM Academy OSINT Fundamentals course, Trace Labs CTF events, and independent self-directed research exercises.