OSWA Exam Prep & Study Resources
OffSec certification · 2 products
WEB-200 | OffSec Web Assessor
Study materials for OSWA
OffSec Web Assessor
OSWA remote passing with payment after passing and EMI options
$399$799
View →OffSec Web Assessor
XSS, CSRF, SQLi, SSRF, XXE, CORS, SSTI, and more
$149$249
View →Frequently asked questions
What is OSWA?
OSWA (Offensive Security Web Assessor) is OffSec's entry-level to intermediate web application security certification, based on the WEB-200 course. It is designed to validate foundational web application penetration testing skills, covering common and impactful vulnerabilities including SQL injection, cross-site scripting, server-side request forgery, and authentication bypass techniques. OSWA targets candidates who want to specialize in web security but are not yet ready for the advanced source-code-review demands of OSWE. It serves as a structured, practical introduction to offensive web testing within the OffSec certification ecosystem.
How hard is OSWA?
OSWA is more approachable than OSWE but should not be underestimated. It is targeted at intermediate-level web application testers and requires genuine hands-on exploitation skills in a controlled environment. The exam presents real web application targets that must be exploited under time pressure without relying on automated scanners alone. Candidates with solid knowledge of the OWASP Top 10 and practical Burp Suite experience will find the difficulty manageable. Those coming from a purely theoretical background may struggle. Thorough completion of the WEB-200 course labs is the most reliable path to passing.
What are the prerequisites for OSWA?
There are no mandatory formal prerequisites for OSWA, but OffSec recommends that candidates have solid familiarity with HTTP and HTTPS protocols, a working understanding of web application architecture (client-server model, cookies, sessions), basic SQL knowledge, and awareness of common OWASP Top 10 vulnerability classes. Practical experience with Burp Suite Community or Professional Edition is strongly recommended since the exam requires intercepting, modifying, and replaying HTTP requests. Candidates who have completed introductory web security courses on TryHackMe or PortSwigger Web Academy will be well prepared for the WEB-200 content.
OSWA vs OSWE, what is the difference?
OSWA and OSWE are both web application security certifications from OffSec but differ substantially in depth and approach. OSWA is entry-level and uses a black-box testing methodology where you assess a running application without access to its source code. OSWE is the advanced counterpart, requiring white-box testing where you read application source code in multiple languages to find and chain complex vulnerabilities. OSWA is the logical stepping stone before OSWE. Candidates who earn OSWA build the web exploitation fundamentals needed to tackle the much more demanding source code analysis and multi-step exploit chain development required by OSWE.
What topics does OSWA cover?
OSWA covers the core categories of web application vulnerabilities from an offensive testing perspective. Topics include SQL injection (union-based, blind, and time-based), cross-site scripting (reflected, stored, and DOM-based), server-side request forgery, authentication and session management flaws, file inclusion (local and remote), OS command injection, and insecure direct object reference vulnerabilities. The WEB-200 course teaches practical exploitation methodology for each vulnerability class with hands-on lab exercises designed to build real skills rather than just theoretical knowledge.
How long to prepare for OSWA?
Most candidates require one to three months of dedicated preparation for OSWA. The WEB-200 course labs, when completed thoroughly and without rushing, provide sufficient preparation for the exam. Supplementing your practice with PortSwigger Web Academy labs (which are free) targeting the same vulnerability classes covered in WEB-200 is highly recommended. Candidates with prior web application security experience or bug bounty hunting backgrounds often find one month of focused study is enough. First-time web security students should plan for closer to two to three months to build solid exploitation habits.
Is OSWA worth it?
Yes. OSWA is a well-structured, practical web application security certification that validates genuine hands-on skills backed by OffSec's respected brand. It serves as an excellent entry point into OffSec's web security certification track and provides a clear credential demonstrating practical offensive web testing ability. OSWA is particularly valuable for penetration testers who want to specialize in application security, bug bounty hunters who want formal recognition of their skills, and professionals preparing for the more advanced OSWE certification. Its practical exam format makes it more credible than knowledge-based alternatives.
What is the OSWA exam format?
The OSWA exam is a four-hour proctored practical assessment. During the exam, you receive access to one or more target web applications and must identify and exploit real vulnerabilities to collect flags demonstrating successful exploitation. Unlike knowledge-based exams, there are no multiple-choice questions, every point requires actual hands-on exploitation. After the hacking session, a penetration test report must be submitted documenting your findings, methodology, and exploitation evidence. The combination of time pressure and report writing closely mirrors real professional web application assessment engagements.