Confidently Practice Online with Free OSWA Exam Cram

Practice your OffSec Web Assessor (OSWA) certification test with free OSWA exam cram and take control of your certification preparation. At FreeExamCram, you can practice online for free using real OSWA exam dumps, verified questions, and expert-designed free online practice tests. Moreover our OffSec OSWA exam cram backed by our confidence-boosting refund guarantee.

Exam Code: OSWA
Exam Questions: 180
OffSec Web Assessor (OSWA)
Updated: 19 Feb, 2026
Viewing Page : 1 - 18
Practicing : 1 - 5 of 180 Questions
Question 1

An image thumbnailer service accepts a url and fetches the image server-side. The server runs inside AWS. You can supply gopher:// URIs.

Which chain most likely yields temporary AWS credentials that let you enumerate S3 buckets in the same account?

Options :
Answer: B

Question 2

* * * * * tar -czf /root/backup.tar /home/user/*

Which filenames trigger escalation? (Select all that apply)

Options :
Answer: A,B

Question 3

You gain SELECT access via SQLi on MySQL. You want SUPER privileges.

What technique applies?

Options :
Answer: D

Question 4

During a penetration test, you find a reflected XSS in a GET parameter ?q=. The web app sets a HttpOnly session cookie. Which of the following BEST allows you to hijack the victim’s authenticated session?

Options :
Answer: B

Question 5

A server validates Host headers strictly to cdn.example.com. You want SSRF against localhost.

Which technique is MOST effective?

Options :
Answer: C

Viewing Page : 1 - 18
Practicing : 1 - 5 of 180 Questions

© Copyrights FreeExamCram 2026. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (FreeExamCram). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreeExamCram.