Exam Code: OSWA
Exam Questions: 180
OffSec Web Assessor (OSWA)
Updated: 04 Sep, 2026
Viewing Page : 1 - 18
Practicing : 1 - 5 of 180 Questions
Question 1

A healthcare portal blocks standard CSRF

submissions, but accepts GET requests with sensitive parameters. You need to trick a logged-in doctor into issuing a prescription refill.

Which payload works best?

Options :
Answer: C

Question 2

A server validates Host headers strictly to cdn.example.com. You want SSRF against localhost.

Which technique is MOST effective?

Options :
Answer: C

Question 3

A user has sudoedit rights on /etc/exports via sudoedit /etc/exports.

How can you escalate to root?

Options :
Answer: C

Question 4

You want to enumerate hidden admin panels on https://corp.example/ while avoiding common noise. Requirements:

Ignore responses with status codes 302 and 403.

Match only responses containing “Admin” or “Control Panel” (case-insensitive).

Randomize User-Agent each request from ua.txt.

Throttle requests to bypass rate-limiting.

Which ffuf command lines satisfy all requirements? (Select all that apply)

Options :
Answer: C

Question 5

A WAF blocks single quotes '. Which payload bypasses it to fetch database()?

Options :
Answer: C

Viewing Page : 1 - 18
Practicing : 1 - 5 of 180 Questions

© Copyrights FreePDFQuestions 2026. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (FreePDFQuestions). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreePDFQuestions.