Exam Code: OSWA
Exam Questions: 180
OffSec Web Assessor (OSWA)
Updated: 20 Feb, 2026
Viewing Page : 1 - 18
Practicing : 1 - 5 of 180 Questions
Question 1

You want to discover hidden parameters influenced by a CDN.

What is the best initial approach in Burp?

Options :
Answer: B

Question 2

During a penetration test, you find a reflected XSS in a GET parameter ?q=. The web app sets a HttpOnly session cookie. Which of the following BEST allows you to hijack the victim’s authenticated session?

Options :
Answer: B

Question 3

During testing, you find a REST endpoint:

GET /api/v1/users/1234/profile

Authenticated as a normal user, you can access your own profile. Changing ID 1234 to 1001 retrieves another user’s data. Which methodology most reliably proves mass exploitation feasibility without detection?

Options :
Answer: D

Question 4

A site implements CSRF protection via double-submit cookies. You notice that SameSite is set to Lax. Which crafted request bypasses protection?

Options :
Answer: D

Question 5

You find:

POST /upload

{"filename":"invoice.pdf","path":"/users/123/docs/"}

Which exploitation demonstrates maximum impact?

Options :
Answer: A

Viewing Page : 1 - 18
Practicing : 1 - 5 of 180 Questions

© Copyrights FreePDFQuestions 2026. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (FreePDFQuestions). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreePDFQuestions.