Menu

The short answer to how does the oscp exam work is this: OffSec gives you VPN access to an isolated network, a hard clock of 23 hours and 45 minutes to compromise a fixed set of machines, and a separate window to submit a professional penetration test report. Your result is decided entirely by the technical access you achieve and how clearly you document it, all under a remote proctor watching your screen and webcam. It is a graded engagement, not a quiz.

That framing matters because it changes how you should prepare. The exam is fixed in structure, scoring, and time, so the real decision is not whether OSCP is hard, but how you match your training to those constraints. Below we break down the mechanics that decide your pass or fail, then help you judge whether an accelerated, mentor-supported route fits your timeline. If you already know you want a guided path, you can move straight to our OSCP Exam Support Services.

Table of contents

What exactly is the OSCP exam?

The Offensive Security Certified Professional exam is a performance-based test from OffSec that validates your ability to run a real penetration test under strict time and documentation rules. There are no multiple-choice questions. You discover vulnerabilities, exploit them, gain low-privilege and then high-privilege access on live targets, and explain your full methodology in a formal report.

Under the current OSCP+ update, OffSec defines the exam structure and rules in its official OSCP exam guide, which is the primary reference for what you may and may not do during the exam. Treat that guide as the authority; everything else, including this article, is preparation context around it. If you want the broader background before the mechanics, our full OSCP certification overview covers what the credential signals to employers.

Infographic showing the OSCP+ exam has five targets, 100 points, a 70-point pass mark, a 23h45 attack window, and no bonus points.
OSCP+ Exam at a Glance

Exam structure: machines, points, and passing score

The OSCP+ format has a fixed structure worth 100 possible points, and you need at least 70 to certify. The targets break down as follows.

Target group Machines Points How points are earned
Standalone hosts 3 independent 60 total 10 for initial access + 10 for full privilege escalation per machine
Active Directory set 3 (typically two clients, one domain controller) 40 total Distributed across the chain (for example 10/10/20), tied to compromising the domain objective

For the AD set, OffSec provides a username and password that simulate a breach scenario, and you must complete the full exploitation chain through the domain. That design is deliberate: partial footholds in the AD set do not translate into partial safety, because the points depend on advancing the overall domain compromise.

One change trips up candidates coming from older material. Bonus points from course labs and exercises, which existed in earlier OSCP versions, are no longer available in OSCP+. Every point now comes directly from your exam compromises and your documentation, which raises the value of both a clean AD chain and a precise report.

If you realise mid-preparation that your AD chaining or privilege escalation is shaky, structured, exam-targeted materials cut down trial-and-error and keep you moving strategically. That is exactly what our OSCP Exam Support Services are built around.

Time windows: exam duration and reporting

OffSec splits your exam into two distinct windows, and confusing them is a costly mistake.

The attack window gives you 23 hours and 45 minutes from your scheduled start to access and exploit the exam network over VPN. When that closes, a separate report submission window opens, giving you an additional period, up to 24 hours in typical descriptions, to submit your penetration test report through the OffSec portal using the required templates.

The clock is the exam’s real adversary. Nearly a full day sounds generous until recon, failed exploits, and rabbit holes eat into it. The format forces you to prioritise, document as you go rather than at the end, and make hard calls about whether to keep grinding a stubborn box or pivot to easier points elsewhere. Candidates who treat those decisions as gut feel on the day tend to run out of time; candidates who rehearse a triage strategy in advance keep momentum.

One purchase instead of months of preparation. Because time never comes back.

Proctoring: how OSCP’s remote monitoring works

OSCP exams are fully proctored, and the technical requirements are strict enough that they deserve rehearsal before exam day. OffSec’s proctored exam requirements FAQ lists typical minimums such as a 64-bit dual-core CPU, 8GB of RAM, and a stable internet connection so the proctoring software can capture your screen and webcam for the entire exam.

You join the proctoring session through a dedicated portal, enter your OSID and MD5 value, and complete pre-exam verification, including ID checks and an environment scan of your room. From there, the monitoring layer works like this:

This is why the exam is procedural as much as technical. Learning tool restrictions and environment rules for the first time on exam day adds avoidable stress at the worst possible moment. Practising with someone who understands both the technical and proctoring side removes that friction.

How the exam actually runs, start to submission

OffSec’s documentation describes the process in discrete steps, but the lived flow for a candidate looks like this.

Before exam day, you schedule your attempt through the OffSec learning platform, confirm your time slot, and receive reminder emails containing your proctoring and VPN details. Shortly before your start time, you log into the OffSec portal, launch the proctoring solution, verify your identity and environment, and then reach the exam dashboard.

During the 23h45 window, you connect to the exam VPN, run reconnaissance across the network, identify the three standalone hosts and the AD set, and begin exploitation. The core tension is balancing depth against breadth: overcommitting to one machine can quietly cost you the 70 points you need. After the VPN closes, you finalise and submit a report that details your methodology, findings, proof of exploitation such as screenshots and commands, and remediation notes for each compromised host, following OffSec’s reporting templates.

The whole design mimics a compressed real-world engagement: limited time, firm rules, and a professional deliverable at the end. If you would rather rehearse against that shape with exam-style tasks, AD scenarios, and reporting expectations instead of assembling everything yourself, that is the gap our OSCP Exam Support Services are designed to close for time-constrained professionals.

Is OSCP the right exam for you?

Choosing OSCP is a decision about how you want to prove your skills, not just about adding a logo to your resume.

OSCP fits you if you want a hands-on, high-pressure exam where success comes from live exploitation rather than theory, you are comfortable working across Linux and Windows environments, running your own tooling, and troubleshooting under time pressure, and you value a credential employers recognise as a difficult, real-skills milestone.

It is less aligned if you prefer multiple-choice formats or purely conceptual content, or if you have very limited time to practice and cannot realistically run several full-day mock exams. For that second group, the choice is rarely OSCP versus nothing. It is OSCP with solo study versus OSCP with compressed, mentor-guided preparation. If cost is part of your decision, our OSCP exam cost breakdown lays out the numbers before you commit.

How to prepare against the exam’s constraints

Because the structure and clock are fixed, good preparation is really about matching your training to those constraints rather than studying broadly and hoping.

With enough runway, self-study plus dedicated lab work can carry you. On a fixed employer deadline or a few hours a week, mentor-guided preparation aligns your practice with the exact machine types, AD scenarios, and reporting style OffSec expects, and removes guesswork. Our guides to the best study resources for OSCP and to how remote exam support works are useful starting points either way.

Don’t let exams steal your months. Take your time back with one purchase.

Where candidates lose points

Understanding how the OSCP exam works also means understanding how strong candidates still fail inside its structure.

Point misallocation is the classic trap: sinking hours into a single 20-point machine and neglecting the rest can leave you under 70 despite genuine skill. The AD set is the second: many candidates gain partial access but never complete the domain compromise, forfeiting the full 40-point opportunity. Poor documentation is the quietest killer, since incomplete reports have failed candidates whose technical work was adequate, because OffSec requires clear, step-by-step evidence. Finally, proctoring problems, from software issues to misunderstood tool rules to environment violations, can disrupt or invalidate an attempt.

Each of these is rehearsable. Practising AD chains to completion and writing full reports under a clock removes most of the risk before you ever schedule the exam.

How we fit into your OSCP journey

We built Cyber Services around OffSec and related certifications, including OSCP, OSWP, OSWE, OSWA, OSEP, OSED, OSDA, CPTS and more, with an emphasis on mentor support, instant delivery, and a success-oriented approach for professionals who need fast, exam-focused readiness instead of slow, broad study.

For someone weighing how the exam works against their available time, the decision usually comes down to two paths: build and manage every practice lab, reporting template, and AD scenario alone, or lean on a mentor-backed resource that already mirrors exam-style scenarios and reporting expectations and is tuned for time-constrained IT and security professionals. If the accelerated, guided route is the right fit for you, the natural next step is to explore our OSCP Exam Support Services and tell us your target exam date so we can shape a focused plan around it.

Frequently asked questions

How long is the OSCP exam?

You have 23 hours and 45 minutes of VPN access to attack the exam network, followed by a separate window, up to 24 hours in typical descriptions, to submit your penetration test report.

How many machines are in the exam, and how are points allocated?

The OSCP+ exam has five targets: three standalone machines worth 20 points each (10 for access, 10 for privilege escalation) and an AD set of three machines worth 40 points total, for 100 points overall.

What score do I need to pass OSCP?

You must earn at least 70 out of 100 points from your machine compromises and documentation to be awarded the OSCP certification.

Are OSCP exams proctored?

Yes. Every OSCP exam is remotely proctored with screen recording, webcam monitoring, and a chat-based proctor interface, and you must meet specific hardware and connection requirements.

Do lab exercises or course work give extra points in OSCP+?

No. In the current OSCP+ format, bonus points are no longer available. Only your exam performance and report count toward the 70-point threshold.

×
?

Secure connection established...

Syncing...
1 / 3
error: Content is protected !!
Contact Us - TG