← Feed
@fifonetworks@infosec.exchange
Post #3525901
2026-07-02 03:12 UTC
“OSCP+ has a ~30% pass rate.”
In that case, the exam is shit, and the official approved study materials are shit.
Background for those not in cybersecurity: OSCP is Offensive Security Certified Professional, a penetration testing exam by OffSec. Someone on LinkedIn, who sells OSCP training, provided that 30% statistic. I don’t know if it’s accurate, but a quick check on Reddit makes it seem likely. I asked OffSec for their pass rate, and they declined, saying they don’t publish that information. If it is around 30%, there’s a big problem at OffSec.
For comparison, CompTIA, another IT and cybersecurity certification company, looks for a first-time pass rate of about 70%. The rationale goes like this: If the pass rate is too high, it means the exam is too easy. On the other hand, if the pass rate is too low, it may indicate poor courseware or a poorly written exam.
When I was teaching the CompTIA courses at a local community college, I used to submit exam inaccuracies for A+, Network+, and Security+ to CompTIA. Some of them resulted in changes, some didn’t. The exam questions that drove me the most crazy were the questions that were vague or ambiguous – not definitively incorrect. And those were the ones they rejected my recommendations on. My guess was they were trying to keep that first-time pass rate from getting too high, and the vague questions were intentionally vague.
Leaving CompTIA, and back to OffSec: I just looked at their website. The current price for the OSCP+ Standalone Exam is $1,699, and includes 2 exam attempts in a 90-day period.
With a 30% first-time pass rate, that means a fair number of applicants are buying a second package. Maybe it’s all about the money.
#cybersecurity
Replies (1)
-
RE: https://infosec.exchange/@fifonetworks/116848192798513192
@fifonetworks@infosec.exchange The certification industry is a racket. Folks I've worked with that touted their certs were not good at their jobs, to a person. Not one. Had a guy, (CCNE I think) who thought that because a competitor put their WiFi AP's near our business to steal our customers, that we could put up our own with their SSID, and overpower the radio. A lawsuit ensued and we lost. I busted the same guy "hacking" the CIO's Lotus Notes by stealing the CIO's id file and he sent a reply to an email to me under that account. Another person, an MCSE, put all the users in the domain admin group. The reason? It decreased the number of requests regarding permissions issues and software installs. All these certs prove is that you can take a test.
Open ##3533529