Exam Code: OSWA
Exam Questions: 180
OffSec Web Assessor (OSWA)
Updated: 24 May, 2026
Viewing Page : 1 - 18
Practicing : 1 - 5 of 180 Questions
Question 1

During testing, you find a REST endpoint:

GET /api/v1/users/1234/profile

Authenticated as a normal user, you can access your own profile. Changing ID 1234 to 1001 retrieves another user’s data. Which methodology most reliably proves mass exploitation feasibility without detection?

Options :
Answer: D

Question 2

* * * * * tar -czf /root/backup.tar /home/user/*

Which filenames trigger escalation? (Select all that apply)

Options :
Answer: A,B

Question 3


What’s the most reliable exploit?

Options :
Answer: D

Question 4

A WAF blocks single quotes '. Which payload bypasses it to fetch database()?

Options :
Answer: C

Question 5

You inject payload:

Which vulnerability chain is demonstrated?

Options :
Answer: A

Viewing Page : 1 - 18
Practicing : 1 - 5 of 180 Questions

© Copyrights FreePDFQuestions 2026. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (FreePDFQuestions). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreePDFQuestions.