The Certified OSWA training program is designed to equip professionals with the essential skills to become proficient in OSWA and cybersecurity.
Through hands-on labs, real-world simulations, and cutting-edge AI-driven tools, participants will become proficient in ethical hacking techniques and critical cybersecurity practices for defending against traditional and modern AI-powered threats.
| Certification Name | OSWA (Practical Exam) |
|---|---|
| Exam Format | Practical Exam |
| Number of Questions | 125 Questions |
| Exam Duration | 24 Hours |
| Passing Score | 70 out of 100 |
| Exam Delivery | OffSec's LearnOne platform |
The WEB-200 course is ideal for: Security professionals seeking to enhance their web application security testing skills Those with knowledge of web development technologies and familiarity with Linux systems
While there are no formal prerequisites, it’s strongly recommended that you have a basic understanding of: Web development technologies (HTML, CSS, JavaScript) Networking Fundamentals Linux operation system basics All of the above can be found in our Web Application Assessment Essentials Learning Path which will give you the skills necessary for success in this course.
Unlike the OSCP+, OSIR, and OSTH, the OffSecWeb Assessor (OSWA) certification does not expire.
The OffSec Web Assessor (OSWA) certification demonstrates your ability to identify and exploit common web application vulnerabilities through a practical, hands-on assessment. It’s ideal for those focused on securing modern web technologies and applications. With OSWA, you’ll be equipped to pursue roles that involve offensive and defensive strategies for web application security, including: Penetration Tester (specializing in web applications) Web Application Security Tester Security Researcher Cloud Security Engineer DevSecOps Engineer Application Security Analyst Software Developer (with a focus on secure coding practices) Bug Bounty Hunter The OSWA is particularly valuable for professionals working with or building web-based systems, as it provides a strong understanding of vulnerabilities like injection attacks, authentication flaws, and client-side issues—all from an attacker’s perspective.
To learn advanced web attacks and exploitation techniques, OffSec also offers the WEB-300 and OSWE certification as well as other certifications in Penetration Testing, Exploit Development, Security Operations, Threat Hunting, and Incident Response.
All of our fully released courses may qualify students for up to 40 (ISC)² CPE credits. To know if you are eligible to request a completion letter or to find course completion requirements, please visit our How can I obtain (ISC)² CPE credits and/or a course completion letter for my course article.