Failed OSCP (Offensive Security Certified Professional)? Here's Your Recovery Plan
Failing an exam doesn't define you. The OSCP (Offensive Security Certified Professional) has a pass rate of ~25%, you're not alone. Here's exactly what to do next.
The OSCP (Offensive Security Certified Professional) has a pass rate of ~25%, which means many qualified candidates don't pass on their first attempt. This is a very hard-difficulty exam that challenges even experienced professionals.
Most people who fail and try again with a better strategy pass on their second attempt. The key is understanding what went wrong and fixing it.
Wait Period
Varies, check with exam provider
Retake Cost
Typically full exam fee
Max Attempts
Varies by provider
Pro tip: Contact the exam provider directly for their specific retake policy.
- Capturing proof file contents through a web shell or by reading the file from outside an interactive shell.OffSec accepts proof only when read with cat or type from their original location inside an interactive shell on the target. Any other method, explicitly including any web-based shell, results in zero points for that machine. Upgrade every web foothold to a real shell before you touch the proof file.
- Taking proof screenshots without the target's IP address in the frame.Each local.txt and proof.txt screenshot must show the file contents and the target IP produced by ipconfig, ifconfig, or ip addr. Missing this zeroes the target. Build the habit now: run the IP command and the cat command in the same terminal, then capture once.
- Burning the Metasploit allowance on the first machine that resists.You may use Metasploit modules or the Meterpreter payload against exactly one machine, and the choice locks in the moment you use either, even if the attack fails. You cannot test with it across machines first, the check command included, and it cannot be used for pivoting at all. msfvenom and exploit/multi/handler remain available against everything. Decide your one target deliberately, late.
- Reaching for sqlmap, Nessus, or an AI chatbot out of habit.The exam bans automatic exploitation tools including sqlmap, mass vulnerability scanners including Nessus and OpenVAS, commercial tools including Burp Pro and Metasploit Pro, spoofing attacks, and all AI chatbots. Nmap with its scripting engine, Nikto, Burp Free, and DirBuster are permitted. Practice without the banned tools so the reflex never forms.
- Leaving the Active Directory set until the second half of the exam.The AD set is 40 of the 100 points, the largest block available, and three of the four published passing combinations depend on earning 20 or 40 points from it. Since November 2024 it starts from a supplied username and password, so no foothold hunt gates it. Nothing stops you opening with the largest block of points while you are freshest.
- Planning to write the report after the exam ends and taking screenshots as an afterthought.You get 24 hours after the exam to upload, but you cannot go back and collect a screenshot you never took. Once submitted, the submission is final and OffSec will neither accept nor request missing material. Write the report section for each machine immediately after you finish that machine.
- Submitting the report in the wrong filename format or in a password-protected archive.The PDF must be named OSCP-OS-XXXXX-Exam-Report.pdf and archived into OSCP-OS-XXXXX-Exam-Report.7z with your OSID, case sensitive, under 200MB, with no password. Anything else is rejected by the upload application. Upload to upload.offsec.com, compare the MD5 the site shows against your local file, then click Submit File.
- Studying the PEN-200 AWS module expecting it on the exam.OffSec has stated that the AWS module was added to the PEN-200 course but is not yet part of the exam. It is worth learning for the job; it is not worth exam hours you could spend on Active Directory or privilege escalation.
- Treating the 23 hour 45 minute window as a continuous session to be powered through.OffSec states plainly that the allotted time takes life into account and that you are expected to take rest breaks, eat, drink, and sleep. Candidates who work 20 straight hours make worse decisions in hour 15 than a rested candidate makes in hour 20. Schedule sleep before the exam starts and keep the webcam running through it.
- Reverting machines carelessly and running out.You get 24 reverts, and that limit can be reset once during the exam. All machines are freshly reverted at the start, so there is no need to revert anything at the beginning. Click the revert button once per attempt and wait, since a revert discards every change you made on that machine.
Analyze Your Score Report
Review your OSCP (Offensive Security Certified Professional) score report immediately. Identify which domains you scored lowest in, these are your priority areas. Write down specific topics you struggled with while the exam is fresh in your memory.
Take a Short Break (But Not Too Long)
Take 2-3 days off from studying to reset mentally. Failing is emotionally draining, and jumping back in immediately can lead to burnout. But don't wait too long, the material is still fresh.
Change Your Study Strategy
Whatever approach you used before didn't work. Switch it up: if you only read textbooks, add video courses. If you didn't do practice tests, make them your primary study method. Active recall beats passive review every time.
Focus on Weak Areas (80/20 Rule)
Spend 80% of your study time on the 2-3 domains where you scored lowest. You probably already know the topics you scored well on. For OSCP (Offensive Security Certified Professional), this targeted approach is far more effective than re-studying everything.
Take a Practice Test Before Rebooking
Don't rebook the exam until you're consistently scoring 85%+ on practice tests. This saves you money and builds real confidence. When you're scoring well, schedule the retake.
- 24-hour hands-on practical exam
- Practice extensively on Hack The Box
- Master enumeration and privilege escalation
- Document everything in your notes
- Try Harder mentality is essential
How long do I have to wait to retake the OSCP (Offensive Security Certified Professional)?
The retake waiting period for OSCP (Offensive Security Certified Professional) is Varies, check with exam provider. Contact the exam provider directly for their specific retake policy.
How much does it cost to retake the OSCP (Offensive Security Certified Professional)?
The retake cost is Typically full exam fee. Maximum attempts: Varies by provider.
What percentage of people fail the OSCP (Offensive Security Certified Professional)?
The OSCP (Offensive Security Certified Professional) has an average pass rate of ~25%, meaning roughly 75% of test-takers fail on their first attempt.
Is the OSCP (Offensive Security Certified Professional) harder the second time?
No, the OSCP (Offensive Security Certified Professional) difficulty is the same on retake. Many people pass on their second attempt because they know what to expect and can focus their study on weak areas.
Ready to pass OSCP (Offensive Security Certified Professional)?
Get the complete exam guide with study plan, resources, and expert tips.
View OSCP (Offensive Security Certified Professional) Guide