Exam Logistics & Methods Flashcards

(13 cards)

1
Q

You got SYSTEM on a Windows box but forgot to screenshot proof.txt in an interactive shell. What’s the scoring risk?

A

High risk of zero points for that target: proof must be shown in a screenshot via cat/type from original location.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

You retrieved proof.txt via a web-based shell and pasted it into notes. Is that acceptable?

A

No—OffSec requires proof shown via an interactive shell with cat/type from original location; web shells can be zero points.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

You found an exploit online and ran it unmodified. What belongs in your report?

A

The URL/source of the exploit, not the full unmodified code.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

You modified an exploit to work. What should you include?

A

Modified code + original URL + highlight changes + explain why changes were made.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

You are stuck 3 hours on one host with no foothold. Best next step?

A

Timebox: pivot to another host or new vector, then return later with fresh recon.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Your notes have commands but no console output. What is the risk?

A

Insufficient documentation can reduce/zero points because steps must be replicable with evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

You have a root shell on Linux but as a different user than expected. What determines full points?

A

Root shell requirement (Linux) plus proof screenshot from original location.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

You forgot which exact payload/port you used for reverse shell. How do you prevent this?

A

Record every command/parameter and keep a per-host timeline in notes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

You want to use an automated tool that might perform restricted actions. What’s best practice?

A

Check OffSec exam restrictions; if unsure, don’t run it during exam and use manual methods.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

You solved all objectives but report is incomplete. Can you pass?

A

Maybe not—documentation is strictly graded; missing required screenshots/steps can cost points.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

You copied sensitive exploit code blocks into the report that you didn’t modify. What should you do?

A

Remove unmodified code and replace with the exploit URL/reference.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

You plan to use ChatGPT during the live exam to draft commands. Is that allowed?

A

No—OffSec states AI chatbots/LLMs with direct prompt access aren’t permitted during the active exam.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

You’re unsure whether to continue after the exam time ends. What’s correct?

A

Stop when the proctored exam time ends; then use the report submission window to write the PDF report.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly